Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in PCRE2 Library

Multiple vulnerabilities in the PCRE2 library allow a remote, unauthenticated attacker to cause a denial of service (DoS) condition or perform sensitive information disclosure.

CVE search metadata

CVE search record: CVE-2024-1586. Severity: medium. CVSS: 6.4. EPSS: 0.37%. KEV: no. Product: PCRE2. Brief: Multiple Vulnerabilities in PCRE2 Library. Brief link: https://feed.craftedsignal.io/briefs/2026-10-pcre-vulnerabilities/

CVE search record: CVE-2024-1587. Severity: medium. CVSS: 5.3. EPSS: 0.58%. KEV: no. Product: PCRE2. Brief: Multiple Vulnerabilities in PCRE2 Library. Brief link: https://feed.craftedsignal.io/briefs/2026-10-pcre-vulnerabilities/

The Perl Compatible Regular Expressions (PCRE2) library contains multiple vulnerabilities that can be exploited by remote, unauthenticated attackers. These vulnerabilities, identified as CVE-2024-1586 and CVE-2024-1587, arise from improper handling of regular expressions during the parsing and execution phases. By providing specially crafted regular expression patterns or input data to applications that utilize the vulnerable PCRE2 library, an attacker can trigger memory management errors. Depending on the implementation, these flaws lead to application crashes, resulting in a Denial of Service (DoS) condition, or potential exposure of sensitive information residing in memory. Because PCRE2 is a foundational component widely integrated into diverse software - including web servers, database systems, and security appliances - the scope of potentially affected infrastructure is significant across Linux, Windows, and macOS environments. Organizations should identify applications bundling the PCRE2 library and monitor security updates from their respective software vendors.

Impact

Successful exploitation of these vulnerabilities can lead to service disruption and potential data leakage. The impact is significant due to the library's ubiquity in middleware and application stacks, where an attacker could crash critical services or potentially leak memory contents, such as encryption keys or session tokens, depending on the specific host application's memory layout.

Recommendation

  • Audit software inventories to identify applications that rely on the PCRE2 library.
  • Prioritize patching for internet-facing applications and network security appliances that use PCRE2 for regex processing.
  • Monitor application logs for unexpected crashes or error patterns indicative of resource exhaustion or memory access violations.

Immediate actions

Inventory systems using PCRE2 and prepare for package updates when vendor patches are released.

IT Operations 72h