CVE-2019-18224: GNU LIBIDN2

Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.

idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.

Affected products

  • GNU LIBIDN2: before 2.1.1 (fixed in 2.1.1)

Published 2019-10-21. Last modified 2026-06-17.