Description
The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
Remediation
References
Related Vulnerabilities
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1000192)
Django Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-45116)
WordPress Plugin Easy Custom Auto Excerpt Cross-Site Scripting (2.4.6)
WordPress Plugin Fast Secure Contact Form Remote Code Execution (4.0.44)