An issue was discovered in libslax through v0.22.1. A NULL pointer dereference exists in the function slaxLexer() located in slaxlexer.c. It allows an attacker to cause Denial of Service.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-39532.json"