[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2019-19246":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T14:55:33.319Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":23,"aliases":24,"duplicate_of":9,"upstream":25,"downstream":26,"duplicates":49,"related":50,"reserved_at":9,"published_at":54,"modified_at":55,"state":56,"summary":57,"references_raw":66,"kevs":96,"epss":97,"epss_history":100,"metrics":362,"affected":372},"CVE-2019-19246","Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-125","Out-of-bounds Read","The product reads data past the end, or before the beginning, of the intended buffer.","weakness","Draft","Base",[19],{"id":20,"name":21,"techniques":22},"CAPEC-540","Overread Buffers",[],[],[],[],[27,29,31,33,35,37,39,41,43,45,47],{"_key":28},"SUSE-SU-2022:3327-1",{"_key":30},"OPENSUSE-SU-2024:11111-1",{"_key":32},"RHSA-2020:5275",{"_key":34},"DLA-2020-1",{"_key":36},"DLA-2431-1",{"_key":38},"MGASA-2020-0029",{"_key":40},"UBUNTU-CVE-2019-19246",{"_key":42},"USN-4460-1",{"_key":44},"DEBIAN-CVE-2019-19246",{"_key":46},"RHSA-2020:3662",{"_key":48},"USN-5662-1",[],[51,52,53],{"_key":28},{"_key":30},{"_key":38},"2019-11-25T16:16:20.000Z","2024-08-05T02:09:39.638Z","Modified",{"cisa_kev":58,"cisa_ransomware":58,"cisa_vendor":9,"epss_severity":59,"epss_score":60,"severity":61,"severity_score":62,"severity_version":63,"severity_source":64,"severity_vector":65,"severity_status":56},false,"low",0.00319,"high",7.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",[67,75,79,85,91],{"url":68,"sources":69,"tags":71},"https://github.com/kkos/oniguruma/commit/d3e402928b6eb3327f8f7d59a9edfa622fec557b",[70,64],"cve.org",[72,73,74],"X Refsource MISC","Patch","Third Party Advisory",{"url":76,"sources":77,"tags":78},"https://bugs.php.net/bug.php?id=78559",[70,64],[72,74],{"url":80,"sources":81,"tags":82},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NO267PLHGYZSWX3XTRPKYBKD4J3YOU5V/",[70,64],[83,84],"Vendor Advisory","X Refsource FEDORA",{"url":86,"sources":87,"tags":88},"https://lists.debian.org/debian-lts-announce/2019/12/msg00002.html",[70,64],[89,90,74],"Mailing List","X Refsource MLIST",{"url":92,"sources":93,"tags":94},"https://usn.ubuntu.com/4460-1/",[70,64],[83,95,74],"X Refsource UBUNTU",[],{"date":98,"score":60,"percentile":99},"2026-06-04",0.55263,[101,105,108,110,113,116,119,122,125,128,131,134,136,139,142,146,149,152,155,158,161,164,167,170,173,176,179,182,185,187,189,192,194,197,199,202,205,208,211,214,217,219,222,225,228,231,234,237,240,243,245,248,251,254,258,261,264,266,268,271,274,276,279,282,285,288,291,294,297,300,303,306,308,311,314,317,320,323,327,330,333,336,339,341,344,347,350,353,356,359],{"date":102,"score":103,"percentile":104},"2025-11-04",0.00193,0.41461,{"date":106,"score":103,"percentile":107},"2025-11-05",0.41451,{"date":109,"score":103,"percentile":104},"2025-11-06",{"date":111,"score":103,"percentile":112},"2025-11-07",0.41491,{"date":114,"score":103,"percentile":115},"2025-11-08",0.41484,{"date":117,"score":103,"percentile":118},"2025-11-09",0.41463,{"date":120,"score":103,"percentile":121},"2025-11-10",0.4143,{"date":123,"score":103,"percentile":124},"2025-11-11",0.41445,{"date":126,"score":103,"percentile":127},"2025-11-12",0.41476,{"date":129,"score":103,"percentile":130},"2025-11-13",0.41492,{"date":132,"score":103,"percentile":133},"2025-11-14",0.41493,{"date":135,"score":103,"percentile":112},"2025-11-15",{"date":137,"score":103,"percentile":138},"2025-11-16",0.41481,{"date":140,"score":103,"percentile":141},"2025-11-17",0.41449,{"date":143,"score":144,"percentile":145},"2025-11-18",0.01431,0.79008,{"date":147,"score":144,"percentile":148},"2025-11-19",0.79013,{"date":150,"score":144,"percentile":151},"2025-11-20",0.79021,{"date":153,"score":103,"percentile":154},"2025-11-21",0.41443,{"date":156,"score":103,"percentile":157},"2025-11-22",0.41447,{"date":159,"score":103,"percentile":160},"2025-11-23",0.41422,{"date":162,"score":103,"percentile":163},"2025-11-24",0.41412,{"date":165,"score":103,"percentile":166},"2025-11-25",0.41425,{"date":168,"score":103,"percentile":169},"2025-11-26",0.41421,{"date":171,"score":103,"percentile":172},"2025-11-27",0.41428,{"date":174,"score":103,"percentile":175},"2025-11-28",0.414,{"date":177,"score":103,"percentile":178},"2025-11-29",0.4138,{"date":180,"score":103,"percentile":181},"2025-11-30",0.41357,{"date":183,"score":103,"percentile":184},"2025-12-01",0.41475,{"date":186,"score":103,"percentile":115},"2025-12-02",{"date":188,"score":103,"percentile":115},"2025-12-03",{"date":190,"score":103,"percentile":191},"2025-12-04",0.41353,{"date":193,"score":103,"percentile":178},"2025-12-05",{"date":195,"score":103,"percentile":196},"2025-12-06",0.41373,{"date":198,"score":103,"percentile":191},"2025-12-07",{"date":200,"score":103,"percentile":201},"2025-12-08",0.4136,{"date":203,"score":103,"percentile":204},"2025-12-09",0.41395,{"date":206,"score":103,"percentile":207},"2025-12-10",0.41454,{"date":209,"score":103,"percentile":210},"2025-12-11",0.41485,{"date":212,"score":103,"percentile":213},"2025-12-12",0.41511,{"date":215,"score":103,"percentile":216},"2025-12-13",0.41494,{"date":218,"score":103,"percentile":207},"2025-12-14",{"date":220,"score":103,"percentile":221},"2025-12-15",0.4144,{"date":223,"score":103,"percentile":224},"2025-12-16",0.41472,{"date":226,"score":103,"percentile":227},"2025-12-17",0.41513,{"date":229,"score":103,"percentile":230},"2025-12-18",0.41557,{"date":232,"score":103,"percentile":233},"2025-12-19",0.4157,{"date":235,"score":103,"percentile":236},"2025-12-20",0.41548,{"date":238,"score":103,"percentile":239},"2025-12-21",0.41509,{"date":241,"score":103,"percentile":242},"2025-12-22",0.41483,{"date":244,"score":103,"percentile":115},"2025-12-23",{"date":246,"score":103,"percentile":247},"2025-12-24",0.41504,{"date":249,"score":103,"percentile":250},"2025-12-25",0.41553,{"date":252,"score":103,"percentile":253},"2025-12-26",0.41532,{"date":255,"score":256,"percentile":257},"2025-12-27",0.0017,0.38819,{"date":259,"score":103,"percentile":260},"2025-12-28",0.41453,{"date":262,"score":103,"percentile":263},"2025-12-29",0.41433,{"date":265,"score":103,"percentile":166},"2025-12-30",{"date":267,"score":103,"percentile":224},"2025-12-31",{"date":269,"score":103,"percentile":270},"2026-01-01",0.41604,{"date":272,"score":103,"percentile":273},"2026-01-02",0.41578,{"date":275,"score":103,"percentile":233},"2026-01-03",{"date":277,"score":103,"percentile":278},"2026-01-04",0.41413,{"date":280,"score":103,"percentile":281},"2026-01-05",0.4139,{"date":283,"score":103,"percentile":284},"2026-01-06",0.41392,{"date":286,"score":103,"percentile":287},"2026-01-07",0.41414,{"date":289,"score":103,"percentile":290},"2026-01-08",0.41442,{"date":292,"score":103,"percentile":293},"2026-01-09",0.41423,{"date":295,"score":103,"percentile":296},"2026-01-10",0.41424,{"date":298,"score":103,"percentile":299},"2026-01-11",0.41394,{"date":301,"score":103,"percentile":302},"2026-01-12",0.41347,{"date":304,"score":103,"percentile":305},"2026-01-13",0.41324,{"date":307,"score":103,"percentile":196},"2026-01-14",{"date":309,"score":103,"percentile":310},"2026-01-15",0.41365,{"date":312,"score":103,"percentile":313},"2026-01-16",0.41388,{"date":315,"score":103,"percentile":316},"2026-01-17",0.41362,{"date":318,"score":103,"percentile":319},"2026-01-18",0.41329,{"date":321,"score":103,"percentile":322},"2026-01-19",0.41294,{"date":324,"score":325,"percentile":326},"2026-01-20",0.00304,0.5318,{"date":328,"score":325,"percentile":329},"2026-01-21",0.53188,{"date":331,"score":325,"percentile":332},"2026-01-22",0.53195,{"date":334,"score":325,"percentile":335},"2026-01-23",0.53236,{"date":337,"score":325,"percentile":338},"2026-01-24",0.53238,{"date":340,"score":325,"percentile":332},"2026-01-25",{"date":342,"score":325,"percentile":343},"2026-01-26",0.53177,{"date":345,"score":325,"percentile":346},"2026-01-27",0.53187,{"date":348,"score":325,"percentile":349},"2026-01-28",0.53204,{"date":351,"score":325,"percentile":352},"2026-01-29",0.53199,{"date":354,"score":325,"percentile":355},"2026-01-30",0.53201,{"date":357,"score":325,"percentile":358},"2026-01-31",0.53209,{"date":360,"score":325,"percentile":361},"2026-02-01",0.53348,[363],{"source":64,"cvss_v2_0":364,"cvss_v3_0":9,"cvss_v3_1":369,"cvss_v4_0":9},{"baseScore":365,"baseSeverity":9,"vectorString":366,"impactScore":367,"exploitabilityScore":368},5,"AV:N/AC:L/Au:N/C:N/I:N/A:P",2.9,10,{"baseScore":62,"baseSeverity":370,"vectorString":65,"impactScore":371,"exploitabilityScore":368},"HIGH",6,[373,382,389,395,405],{"ecosystem":9,"name":374,"vendor":375,"product":376,"cpe_part":377,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":378},"ubuntu linux","canonical","ubuntu_linux","o",[379],{"version":380,"is_range":58,"range_type":381,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"14.04","cpe",{"ecosystem":9,"name":383,"vendor":384,"product":385,"cpe_part":377,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":386},"debian linux","debian","debian_linux",[387],{"version":388,"is_range":58,"range_type":381,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"8.0",{"ecosystem":9,"name":390,"vendor":391,"product":390,"cpe_part":377,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":392},"fedora","fedoraproject",[393],{"version":394,"is_range":58,"range_type":381,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"31",{"ecosystem":9,"name":396,"vendor":397,"product":396,"cpe_part":398,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":399},"oniguruma","oniguruma_project","a",[400],{"version":401,"is_range":402,"range_type":381,"version_start":9,"version_start_type":9,"version_end":403,"version_end_type":404,"fixed_in":9},"lte6.9.3",true,"6.9.3","including",{"ecosystem":9,"name":406,"vendor":9,"product":406,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":407},"PHP",[408],{"version":409,"is_range":402,"range_type":381,"version_start":410,"version_start_type":404,"version_end":411,"version_end_type":412,"fixed_in":9},"gte7.3.0_lt7.3.10","7.3.0","7.3.10","excluding"]