In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-35266.json"