CVE-2019-16396: Gnucobol Project Gnucobol

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

GnuCOBOL 2.2 has a use-after-free in the end_scope_of_program_name() function in cobc/parser.y via crafted COBOL source code.

Affected products

Published 2019-09-17. Last modified 2026-06-17.