In the GNU C Library (aka glibc or libc6) through 2.29, proceednextnode in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-9169.json"