libboron in Boron 2.0.8 has a heap-based buffer overflow in urparseBlockI at iparse_blk.c.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-40294.json"