CVE-2026-31969: Postfix Decrement Bounds Check Oobcve-2026-31969-postfix-decrement-bounds-check-oob
A loop reads from a pointer before performing bounds checking or checking remaining capacity, leading to potential out-of-bounds reads. Furthermore, using postfix decrement (`term-- < 0`) inside the loop causes off-by-one capacity failures, potentially leading to a one-byte buffer overflow (OOB write). Check limits before pointer dereference using a prefix d