← Vulnerability feed

Vulnerability record · CVE-2015-8381 · published 2 December 2015

CVE-2015-8381: Pcre perl compatible regular expression library memory buffer overflow vulnerability

Pcre · Perl Compatible Regular Expression Library

The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R')(\k'R')|((?'R')))H'Rk'Rf)|s(?'R'))))/ and /(?J:(?|(:(?|(?'R')(\z(?|(?'R')(\k'R')|((?'R')))k'R')|((?'R')))H'Ak'Rf)|s(?'R')))/ patterns, and related patterns with certain group references, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

7.5 CVSS 2.0 High EPSS 5.3% · top 7.7% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
5.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R')(\k'R')|((?'R')))H'Rk'Rf)|s(?'R'))))/ and /(?J:(?|(:(?|(?'R')(\z(?|(?'R')(\k'R')|((?'R')))k'R')|((?'R')))H'Ak'Rf)|s(?'R')))/ patterns, and related patterns with certain group references, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-8381 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-8394Pcre perl compatible regular expression library integer overflow vulnerabilityPCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overfl…EPSS 4.8%9.8CVE-2015-8390Pcre perl compatible regular expression library use of uninitialized resource vulnerabilityPCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized …EPSS 4.7%9.8CVE-2015-8389Pcre perl compatible regular expression library memory buffer overflow vulnerabilityPCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite re…EPSS 3.9%9.8CVE-2015-8386Pcre perl compatible regular expression library memory buffer overflow vulnerabilityPCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a den…EPSS 7.1%9.8CVE-2015-8383Pcre perl compatible regular expression library memory buffer overflow vulnerabilityPCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or poss…EPSS 6.1%7.5CVE-2015-8395Pcre perl compatible regular expression library memory buffer overflow vulnerabilityPCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly have unspecified other impact …EPSS 3.5%7.5CVE-2015-8393Pcre perl compatible regular expression library information exposure vulnerabilitypcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a craf…EPSS 4.4%7.5CVE-2015-8392Pcre perl compatible regular expression library memory buffer overflow vulnerabilityPCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of service (unintended recursion …EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2015-8381), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.