That’s a pretty cool find. It just goes to show even some of the oldest and most widely used open source libraries still have security issues. This is a rare corner case but it’s still a fantastic find. I suppose no static analysis tools found it over all those years.