CVE-2026-89162

Public on 2026-09-11
Modified on 2026-09-11
Description
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
2.9
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core pcre Not Affected
Amazon Linux 2023 pcre Not Affected
Amazon Linux 2 - Core pcre2 Not Affected
Amazon Linux 2023 pcre2 Not Affected
Amazon Linux 2027 Preview pcre2 Pending Fix
Amazon Linux 2 - Php8.2 Extra php Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N