The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.
Cite this page
CVE-2015-2325. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2015-2325
Use CWE-125, Pcre vendor hub and Pcre product page to widen CVE-2015-2325 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2015-5073, CVE-2017-7246 and CVE-2017-7245 for nearby disclosures in the same product family.