The Oniguruma Project maintains a regular-expression parsing library widely embedded across scripting languages and text-processing applications, giving its vulnerabilities broad downstream impact despite a narrow product portfolio. Vulnerabilities affecting this library skew strongly toward critical-severity outcomes and recur through memory-safety weakness classes including out-of-bounds reads and writes, NULL pointer dereferences, integer overflows, and uncontrolled recursion—flaws characteristic of the parsing complexity and native-code performance demands of regex engines. Defenders should inventory products that bundle this library and prioritize patches, since a single parsing flaw can compromise every downstream application that processes untrusted input; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oniguruma Project over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19012CRITICAL An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the con | Nov 17, 2019 | 9.8 | 35 | NO | NO |
CVE-2017-9226CRITICAL An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write or read occurs in next_stat | May 24, 2017 | 9.8 | 34 | NO | NO |
CVE-2017-9228CRITICAL An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write occurs in bitset_set_range( | May 24, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-9227CRITICAL An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in mbc_enc_len() dur | May 24, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-9224CRITICAL An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in match_at() during | May 24, 2017 | 9.8 | 33 | NO | NO |
CVE-2019-13224CRITICAL A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by | Jul 10, 2019 | 9.8 | 32 | NO | NO |
CVE-2017-9225CRITICAL An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_cas | May 24, 2017 | 9.8 | 31 | NO | NO |
CVE-2019-19204HIGH An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called with | Nov 21, 2019 | 7.5 | 27 | NO | NO |
CVE-2017-9229HIGH An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A SIGSEGV occurs in left_adjust_char_head() during reg | May 24, 2017 | 7.5 | 27 | NO | NO |
CVE-2019-19246HIGH Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c. | Nov 25, 2019 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oniguruma Project.
Media articles that mention a CVE ID that affects a product developed by Oniguruma Project — matched by CVE ID, not by vendor name.