{"schema_version":"1.8.0","id":"CVE-2019-13224","published":"2019-07-10T14:15:11.607Z","modified":"2026-08-07T14:49:56.686162Z","related":["ALSA-2020:3662","ALSA-2024:0889","SUSE-SU-2022:3327-1","openSUSE-SU-2024:11111-1"],"details":"A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onig_new_deluxe(). Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kkos/oniguruma","events":[{"introduced":"83572e983928243d741f61ac290fc057d69fefc3"},{"last_affected":"83572e983928243d741f61ac290fc057d69fefc3"},{"fixed":"0f7f61ed1b7b697e283e37bd2d731d0bd57adb55"}],"database_specific":{"cpe":"cpe:2.3:a:oniguruma_project:oniguruma:6.9.2:-:*:*:*:*:*:*","extracted_events":[{"introduced":"6.9.2-NA"},{"last_affected":"6.9.2-NA"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["6.9.2-NA","v6.9.2_rc3","v6.9.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13224.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["144477375847041035196488014531602342496","39487835141121000899975727629951651164","243574904145470851950892010676215846309","261101043450223522914619713906777460104","192845130568107495712244117068883375560","38824287918157113434026198298701563168","44502028448723226475273193052058068900","57330471737783644434537330796049609549","265399586591815778503620908494229098639","17751534671408493758106039438651136950","42363307028960740653651765099861536532"],"threshold":0.9},"id":"CVE-2019-13224-69a60e05","signature_type":"Line","signature_version":"v1","source":"https://github.com/kkos/oniguruma/commit/0f7f61ed1b7b697e283e37bd2d731d0bd57adb55","target":{"file":"src/regext.c"}},{"deprecated":false,"digest":{"function_hash":"16716532786252836573114105484968648519","length":884},"id":"CVE-2019-13224-b47700ae","signature_type":"Function","signature_version":"v1","source":"https://github.com/kkos/oniguruma/commit/0f7f61ed1b7b697e283e37bd2d731d0bd57adb55","target":{"file":"src/regext.c","function":"onig_new_deluxe"}}],"vanir_signatures_modified":"2026-08-07T14:49:56Z"}},{"ranges":[{"type":"GIT","repo":"https://github.com/php/php-src","events":[{"introduced":"0221e9f827632942225586687a33cfd554860d5e"},{"fixed":"481520d3819b0b68b65539ff59b4bd2f018d6e5f"},{"introduced":"8148cbb78841c8ec0759c0836e7f35dec799d300"},{"fixed":"b4140bf64811b97af153a5d49a1d71677993a075"},{"introduced":"52ace952a1b65ca80fc2617f11c2fa6dd03f51bd"},{"fixed":"89dc78e0f0c1a4f27b889f232b109a3919ecf478"}],"database_specific":{"cpe":"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.1.0"},{"fixed":"7.1.32"},{"introduced":"7.2.0"},{"fixed":"7.2.23"},{"introduced":"7.3.0"},{"fixed":"7.3.9"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13224.json"}}],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JWCPDTZOIUKGMFAD5NAKUB7FPJFAIQN5/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SNL26OZSQRVLEO6JRNUVIMZTICXBNEQW/"},{"type":"WEB","url":"https://support.f5.com/csp/article/K00103182?utm_source=f5support&amp%3Butm_medium=RSS"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00013.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201911-03"},{"type":"ADVISORY","url":"https://support.f5.com/csp/article/K00103182"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4088-1/"},{"type":"FIX","url":"https://github.com/kkos/oniguruma/commit/0f7f61ed1b7b697e283e37bd2d731d0bd57adb55"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*"],"extracted_events":[{"introduced":"12.04"},{"last_affected":"12.04"},{"introduced":"14.04"},{"last_affected":"14.04"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"},{"cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"29"},{"last_affected":"29"},{"introduced":"30"},{"last_affected":"30"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}