CVE-2026-86145
CVE Details
Visit the official vulnerability details page for CVE-2026-86145 to learn more.
Initial Publication
09/05/2026
Last Update
09/09/2026
Third Party Dependency
pcre2
NIST CVE Summary
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).
CVE Severity
Our Official Summary
Investigation is ongoing to determine how this vulnerability affects our products.
Status
Deferred
Affected Products & Versions
| Version | PaletteAI | PaletteAI VerteX |
|---|---|---|
| 1.4.0 | ⚠️ Impacted | ⚠️ Impacted |
| 1.3.2 | ⚠️ Impacted | ⚠️ Impacted |
| 1.2.2 | ⚠️ Impacted | ⚠️ Impacted |
Revision History
No revisions available.