Unrated severityNVD Advisory· Published Dec 2, 2015· Updated May 6, 2026
CVE-2015-2327
CVE-2015-2327
Description
PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patterns with certain internal recursive back references, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Affected products
1- cpe:2.3:a:pcre:perl_compatible_regular_expression_library:*:*:*:*:*:*:*:*Range: <=8.35
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7News mentions
0No linked articles in our index yet.