In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokeehandlercgiaddenvpair in handlercgi.c by sending many request headers, as demonstrated by a GET request with many "Host: 127.0.0.1" headers.
{ "versions": [ { "introduced": "0" }, { "last_affected": "1.2.104" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-20800.json"