PT-2026-47240 · Unknown · Tiny-Regex-C

·

CVE-2026-11478

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions kokke tiny-regex-c versions prior to f2632c6d9ed25272987471cdb8b70395c2460bdb
Description A flaw in the Pattern Handler component affects the matchstar() function within the re.c file. This issue allows for inefficient regular expression complexity, which can be triggered via local execution.
Recommendations As a temporary workaround, restrict the use of the matchstar() function until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11478

Affected Products

Tiny-Regex-C