Description
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1756-1 | libxslt security update |
EUVD |
EUVD-2022-5058 | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded. |
Github GHSA |
GHSA-qxcg-xjjg-66mj | Nokogiri vulnerable to libxslt protection mechanism bypass |
Ubuntu USN |
USN-3947-1 | Libxslt vulnerability |
Ubuntu USN |
USN-3947-2 | Libxslt vulnerability |
References
History
Thu, 28 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
Cloud Backup
Subscribe
E-series Santricity Management Plug-ins
Subscribe
E-series Santricity Os Controller
Subscribe
E-series Santricity Storage Manager
Subscribe
E-series Santricity Unified Manager
Subscribe
E-series Santricity Web Services Proxy
Subscribe
Element Software
Subscribe
Hci Management Node
Subscribe
Oncommand Insight
Subscribe
Oncommand Workflow Automation
Subscribe
Plug-in For Symantec Netbackup
Subscribe
Santricity Unified Manager
Subscribe
Snapmanager
Subscribe
Solidfire
Subscribe
Steelstore Cloud Integrated Storage
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Oracle
Subscribe
Jdk
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Xmlsoft
Subscribe
Libxslt
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-28T18:18:27.604Z
Reserved: 2019-04-10T00:00:00.000Z
Link: CVE-2019-11068
Updated: 2024-08-04T22:40:16.229Z
Status : Modified
Published: 2019-04-10T20:29:01.147
Modified: 2026-05-28T19:16:28.143
Link: CVE-2019-11068
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-284
Improper Access Control
- NVD-CWE-noinfo
Debian DLA
EUVD
Github GHSA
Ubuntu USN