Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
{
"unresolved_ranges": [
{
"vendor_product": "domoticz:domoticz",
"cpes": [
"cpe:2.3:a:domoticz:domoticz:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "4.10579"
}
],
"source": "CPE_RANGE"
},
{
"extracted_events": [
{
"fixed": "4.10579"
}
],
"source": "DESCRIPTION"
}
]
}"2026-07-08T23:59:03Z"
[
{
"id": "CVE-2019-10678-1d226bba",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"74400263139303292541042905941121580087",
"58449022438561187271251443905869638162",
"105773221344332857631466185116022338757",
"295820779245057703330105003374258619797"
]
},
"source": "https://github.com/domoticz/domoticz/commit/2119afbe74ee0c914c1d5c4c859c594c08b0ad42",
"target": {
"file": "main/Helper.cpp"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10678.json"