← Back to browse · API

CVE-2019-11068

Severity
CRITICAL
CVSS
9.8
EPSS
0.0523
Risk score
41.03
CISA KEV
No
PoC
No
Published
2019-04-10
Modified
2026-05-28
First seen
2026-08-07
Aliases
EUVD-2022-5058, GHSA-QXCG-XJJG-66MJ
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-5058

Description

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

References