{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pcre2--19.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pcre:pcre2:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.4,"id":"CVE-2024-6727"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PCRE2 (\u003c 19.0.0)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","pcre2","cve-2024-6727"],"_cs_type":"advisory","_cs_vendors":["University of Cambridge"],"content_html":"\u003cp\u003eThe PCRE2 (Perl Compatible Regular Expressions) library is affected by multiple security vulnerabilities that allow remote, unauthenticated attackers to perform Denial of Service (DoS) attacks. These vulnerabilities stem from the way the library processes complex or specially crafted regular expression patterns. By submitting a malicious pattern to an application that utilizes an affected version of PCRE2, an attacker can induce excessive resource consumption, specifically CPU and memory exhaustion. This leads to the application becoming unresponsive or crashing, effectively denying service to legitimate users. Because PCRE2 is a widely used dependency in numerous software packages, web servers, and security tools, the impact of these vulnerabilities is broad across various environments. Defenders should identify internal applications relying on PCRE2 and monitor for abnormal CPU spikes or service availability issues potentially linked to malformed inputs.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in service interruption and potential application crashes, impacting system availability for any software that utilizes the vulnerable PCRE2 library. This poses a risk to service level agreements and operational stability across web-facing and internal processing applications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize auditing software inventories to identify applications statically or dynamically linked with vulnerable versions of the PCRE2 library. Follow the upstream patch cycle from the University of Cambridge for PCRE2 to resolve CVE-2024-6727. Implement resource limits (ulimit, cgroups, or application-level request timeouts) on processes that accept untrusted regular expression input to mitigate the impact of excessive resource consumption.\u003c/p\u003e\n","date_modified":"2026-10-07T16:53:07Z","date_published":"2026-10-07T16:53:07Z","id":"https://feed.craftedsignal.io/briefs/2026-10-pcre2-dos/","summary":"Multiple vulnerabilities in the PCRE2 library, including CVE-2024-6727, allow remote, unauthenticated attackers to trigger a Denial of Service condition through crafted regular expressions.","title":"Denial of Service Vulnerabilities in PCRE2 Library","url":"https://feed.craftedsignal.io/briefs/2026-10-pcre2-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - PCRE2 (\u003c 19.0.0)","version":"https://jsonfeed.org/version/1.1"}