CVE-2026-103111
HighAdvisory
Published 30 Sept 2026In the index since 1 Oct 2026
- Severity
- High
- worst across findings
- CVSS
- 7.6
- base score, highest
- EPSS
- 0.002
- 10th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,669
- of 17,985 indexed, latest versions
- Container images
- 2,624
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
CVE-2026-103111 affecting package pcre2 10.48-1
Carried by container images the latest versions of 2,669 of 17,985 indexed charts deploy, on 2,624 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pcre2deb | 10.21-1, 10.34-7, 10.34-7ubuntu0.1, 10.39-3+ubuntu20.04.1+deb.sury.org+2+13 more | 10.46-1~deb13u3 | 2,420 |
| pcre2apk | 10.47-r0, 10.47-r1, 10.48-r0 | 10.49-r0 | 197 |
| pcre2rpm | 10.42-3.azl3 | no fix listed | 7 |
- OSV records
- ALPINE-CVE-2026-103111DEBIAN-CVE-2026-103111UBUNTU-CVE-2026-103111AZL-105119ECHO-bf42-43c6-45fd
- Trending
- Rank 1 in indexed charts, since 1 Oct 2026. See the ranking →
Charts affected
2,669 by stars
Container images carrying it
2,624 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 64af3819f927 | pcre2 | no fix listed | 3 |
| library/ | 008173c23f95 | pcre2 | no fix listed | 3 |
| library/ | 7d0f24ebb67b | pcre2 | no fix listed | 3 |
| mcp/ | 9362bcf6aa0e | pcre2 | no fix listed | 3 |
| meshery/ | 44b64ee128fb | pcre2 | no fix listed | 3 |
| nginxinc/ | adf5042a17f4 | pcre2 | 10.49-r0 | 3 |
| opencloudeu/ | 6e8b2df6c5a4 | pcre2 | no fix listed | 3 |
| opencsghq/ | b98600564e07 | pcre2 | 10.46-1~deb13u3 | 3 |
| openebs/ | f6c18b0f8c8a | pcre2 | no fix listed | 3 |
| openebs/ | 6afe2123c457 | pcre2 | no fix listed | 3 |
| selenium/ | 02f251d48d5f | pcre2 | no fix listed | 3 |
| sigp/ | 50f66cfebb6d | pcre2 | no fix listed | 3 |
| swaggerapi/ | f9b8432be04e | pcre2 | 10.49-r0 | 3 |
| vaultwarden/ | 1587c45feaa4 | pcre2 | 10.46-1~deb13u3 | 3 |
| vaultwarden/ | ebdfe70701c6 | pcre2 | 10.46-1~deb13u3 | 3 |
| ghcr.io/ | f65f53dd9668 | pcre2 | no fix listed | 3 |
| ghcr.io/ | d1036b07e348 | pcre2 | 10.49-r0 | 3 |
| ghcr.io/ | 19ebe07b4daf | pcre2 | no fix listed | 3 |
| ghcr.io/ | a48f82c2c437 | pcre2 | 10.49-r0 | 3 |
| ghcr.io/ | 6a5594b7b32c | pcre2 | no fix listed | 3 |
| ghcr.io/ | 34df3680db1c | pcre2 | no fix listed | 3 |
| ghcr.io/ | 896fc7b18b1b | pcre2 | no fix listed | 3 |
| ghcr.io/ | f0fb462299af | pcre2 | 10.49-r0 | 3 |
| ghcr.io/ | 3e6710a7ab2a | pcre2 | 10.49-r0 | 3 |
| ghcr.io/ | 0502794a4d86 | pcre2 | no fix listed | 3 |
| ghcr.io/ | be083133dfe0 | pcre2 | no fix listed | 3 |
| ghcr.io/ | 5fa76604a81d | pcre2 | 10.46-1~deb13u3 | 3 |
| ghcr.io/ | 673d5229df1f | pcre2 | no fix listed | 3 |
| ghcr.io/ | c5153b5f079c | pcre2 | no fix listed | 3 |
| public.ecr.aws/ | 8b9208c09d76 | pcre2 | no fix listed | 3 |
| quay.io/ | cb009167015c | pcre2 | 10.49-r0 | 3 |
| quay.io/ | 2939231d0d3e | pcre2 | no fix listed | 3 |
| quay.io/ | 6545dac92173 | pcre2 | no fix listed | 3 |
| quay.io/ | 2b6db27eaf3d | pcre2 | no fix listed | 3 |
| quay.io/ | 5bf041aacadd | pcre2 | no fix listed | 3 |
| quay.io/ | 60566529446a | pcre2 | no fix listed | 3 |
| quay.io/ | 721b5c9634d4 | pcre2 | no fix listed | 3 |
| quay.io/ | 9795f3f9f031 | pcre2 | no fix listed | 3 |
| quay.io/ | 39f2c6e0af38 | pcre2 | no fix listed | 3 |
| quay.io/ | 01d5d8c4cecb | pcre2 | no fix listed | 3 |
| quay.io/ | f296c2ec5db7 | pcre2 | no fix listed | 3 |
| quay.io/ | 9d25865295af | pcre2 | no fix listed | 3 |
| quay.io/ | ea6dd1e4ce71 | pcre2 | no fix listed | 3 |
| quay.io/ | 709c7da19c5a | pcre2 | no fix listed | 3 |
| actualbudget/ | 552beab3dec8 | pcre2 | no fix listed | 2 |
| alazidis/ | 0e8c84152201 | pcre2 | no fix listed | 2 |
| alpine/ | 0b5f57d22181 | pcre2 | 10.49-r0 | 2 |
| alpine/ | 832b1cd1a271 | pcre2 | 10.49-r0 | 2 |
| alpine/ | 048f8d9c8cc7 | pcre2 | 10.49-r0 | 2 |
| apache/ | 0116fb802786 | pcre2 | no fix listed | 2 |