Vulnerability Details CVE-2026-89162
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 1.2%
CVSS Severity
CVSS v3 Score 2.9
Products affected by CVE-2026-89162
-
cpe:2.3:a:pcre:pcre2:10.45
-
cpe:2.3:a:pcre:pcre2:10.46
-
cpe:2.3:a:pcre:pcre2:10.47
-
cpe:2.3:a:pcre:pcre2:10.48