CVE-2019-18224: GNU LIBIDN2
Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.
idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.
Affected products
- GNU LIBIDN2: before 2.1.1 (fixed in 2.1.1)
Published 2019-10-21. Last modified 2026-06-17.