In Oniguruma, an attacker able to supply a regular expression for compilation may be able to overflow a buffer by one byte in concatoptexact_str in src/regcomp.c (CVE-2020-26159).
{ "section": "core" }