[security][CVE-2026-89161] PCRE2 in Bun and Redis runtime images #173
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Newly reported active High CVE from the 2026-09-16 scan. New means not previously reported by this automation; some disclosures predate this run. Correction: earlier scans incorrectly dropped Trivy status
fixed, which means a patch is available, not installed.CVE: CVE-2026-89161
Severity: High. CVSS: redhat: 7.4
Affected versions
deb13u1; distro fix 10.46-1deb13u2Project impact
The Dockerfiles use oven/bun:1.3.11 and Compose uses redis:7.2. Both resolved linux/amd64 images contain the affected PCRE2 library. This is inherited OS-library exposure. Application-triggered exploitation is not established: it requires the PCRE2 API usage described below, not ordinary JavaScript regular expressions. Patch the inherited library to remove the vulnerable code.
Advisory description
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
Remediation
Use rebuilt image tags/digests containing the distro fixes listed below, or PCRE2 10.48 or later. Rebuild app images, then rescan the exact resulting digests. Do not assume that a floating tag has picked up the fix.
Run counters, globally deduplicated by CVE ID
unaddressed critical CVEs: 6
unaddressed medium/low CVEs: 184
unaddressed total CVEs: 271
These are unresolved installed-version matches after explicit exclusions, not a claim that every inherited component is remotely exploitable. One UNKNOWN-severity record is retained separately and excluded from the requested severity total. Python requirements and apt-installed Python packages are unpinned, so their deployed versions cannot be established from this repository.
Resolution checks
Paginated all 171 Forgejo issue records and 101 PRs; checked local all-ref history. No matching CVE report or clear fixing change was found for this CVE. Its CVE registry state is PUBLISHED without a disputed tag. Existing reports for other flaws in the same component do not establish a fix for this one.
Sources