Launchpad.net

CVE 2019-19246

Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

See the CVE page on Mitre.org for more details.