njs through 0.3.3, used in NGINX, has a buffer over-read in nxtutf8decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.
{ "versions": [ { "introduced": "0" }, { "last_affected": "0.3.3" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13067.json"