x509constraintsparsemailbox in lib/libcrypto/x509/x509constraints.c in LibreSSL through 3.4.0 has a stack-based buffer over-read. When the input exceeds DOMAINPARTMAX_LEN, the buffer lacks '\0' termination.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-41581.json"