In tmux before version 3.1c the function inputcsidispatchsgrcolon() in file input.c contained a stack-based buffer-overflow that can be exploited by terminal output.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/alpine/ALPINE-CVE-2020-27347.json"