CVE-2016-3191 is a critical vulnerability affecting PCRE 8.x before 8.39 and PCRE2 before 10.22, specifically within the compile_branch function. It allows remote attackers to achieve arbitrary code execution or a denial of service via a stack-based buffer overflow by crafting a malicious regular expression containing an (*ACCEPT) substring and nested parentheses. This vulnerability carries a CVSS score of 9.8 (Critical), indicating a high-impact, easily exploitable threat with no user interaction required. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.00CPE matchmatch criteria | cpe:2.3:a:pcre:pcre:8.00:*:*:*:*:*:*:* | ||
8.01CPE matchmatch criteria | cpe:2.3:a:pcre:pcre:8.01:*:*:*:*:*:*:* | ||
8.02CPE matchmatch criteria | cpe:2.3:a:pcre:pcre:8.02:*:*:*:*:*:*:* | ||
8.10CPE matchmatch criteria | cpe:2.3:a:pcre:pcre:8.10:*:*:*:*:*:*:* | ||
8.11CPE matchmatch criteria | cpe:2.3:a:pcre:pcre:8.11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.