{
  "affected": [
    {
      "database_specific": {
        "unresolved_ranges": [
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "19.10"
              }
            ]
          },
          {
            "events": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "20.04"
              }
            ]
          }
        ]
      },
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "1.3"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "e1901b71c6414c510f10f4cc30c0a05600e55ed1"
            },
            {
              "fixed": "c4603ba5ce229db83a2a4fb93e6d4b4e3ec3776a"
            }
          ],
          "repo": "https://github.com/skvadrik/re2c",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme.",
  "id": "CVE-2020-11958",
  "modified": "2026-04-01T23:10:35.069958340Z",
  "published": "2020-04-21T01:15:11.570Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security.gentoo.org/glsa/202007-28"
    },
    {
      "type": "ADVISORY",
      "url": "https://usn.ubuntu.com/4338-1/"
    },
    {
      "type": "ADVISORY",
      "url": "https://usn.ubuntu.com/4338-2/"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.openwall.com/lists/oss-security/2020/04/19/1"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.openwall.com/lists/oss-security/2020/04/21/1"
    },
    {
      "type": "ADVISORY",
      "url": "https://blogs.gentoo.org/ago/2020/04/19/re2c-heap-overflow-in-scannerfill-scanner-cc/"
    },
    {
      "type": "FIX",
      "url": "https://github.com/skvadrik/re2c/commit/c4603ba5ce229db83a2a4fb93e6d4b4e3ec3776a"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}