Version 10.49 28-September-2026 ------------------------------- This is a security-only release, to address GHSA-r9hj-j2rw-4q3m. Compared to 10.48, this release has only a minimal code change to prevent an out-of-bounds write with arbitrary data. An attacker-controlled regex pattern is required, and applications are only affected if using the pcre2_jit_stack_create() and pcre2_jit_stack_assign() APIs to provide a growable JIT stack, and then matching against a pattern with unusually high JIT stack usage, such as a large number of capturing groups. The implications of an out-of-bounds write could include arbitrary code execution. The issue is not a regression and affects releases 10.48 and earlier.