Fedora has issued an advisory on March 30: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6MG7AZPSDWFYYBHU7RJBZSGWPE5TTNVJ/ The issue appears to be caused by a bundled pcre library.
CVE: (none) => CVE-2016-10253
Fixed in cauldron
Resolution: (none) => FIXEDStatus: NEW => RESOLVED