libxslt: xsltCheckRead and xsltCheckWrite routines security bypass by crafted URL
Published Apr 10, 2019
9.8
CRITICALCVSS 3.1
EPSS 5.23%
Description
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
Affected products
No data.
Configuration 2
- 12.04
- 14.04
- 16.04
- 18.04
- 18.10
Configuration 3
- 8.0
Configuration 4
- 29
- 30
Configuration 6
- n/a
- n/a
- n/a
- n/a
- ≥ 11.0 · ≤ 11.70.2
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
Red Hat Enterprise Linux 7
libxslt-0:1.1.28-6.el7
Fixed · RHSA-2020:4005
Red Hat Enterprise Linux 8
libxslt-0:1.1.32-5.el8
Fixed · RHSA-2020:4464
Red Hat Enterprise Linux 8
libxslt-0:1.1.32-5.el8
Fixed · RHSA-2020:4464
Red Hat Enterprise Linux 5
libxslt
Will not fix
Red Hat Enterprise Linux 6
libxslt
Will not fix
Red Hat OpenStack Platform 10 (Newton)
libxslt
Will not fix
Red Hat OpenStack Platform 13 (Queens)
libxslt
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
libxslt
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
libxslt
Will not fix
Red Hat Storage 3
libxslt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | libxslt-0:1.1.28-6.el7 | Fixed | RHSA-2020:4005 |
| Red Hat Enterprise Linux 8 | libxslt-0:1.1.32-5.el8 | Fixed | RHSA-2020:4464 |
| Red Hat Enterprise Linux 8 | libxslt-0:1.1.32-5.el8 | Fixed | RHSA-2020:4464 |
| Red Hat Enterprise Linux 5 | libxslt | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | libxslt | Will not fix | n/a |
| Red Hat OpenStack Platform 10 (Newton) | libxslt | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | libxslt | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | libxslt | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | libxslt | Will not fix | n/a |
| Red Hat Storage 3 | libxslt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack will consume fixes from the base Red Hat Enterprise Linux Operating System. Therefore the package provided by Red Hat OpenStack has been marked as will not fix.
Red Hat mitigation
This flaw only applies to applications compiled against libxml2 which use xsltCheckRead and xsltCheckWrite functions and/or allow users to load arbitrary URLs to be parsed via libxml2. In all other cases, applications are not vulnerable.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 28, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 5.23% (0.05230) | 92.27th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.23% (0.05230) | 91.42th | v5 (v2026.06.15) |
| Nov 21, 2025 | 1.01% (0.01011) | 76.43th | v4 (v2025.03.14) |
| Nov 18, 2025 | 3.01% (0.03013) | 85.37th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.52% (0.00522) | 64.23th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.49% (0.02491) | 75.51th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.52% (0.00522) | 64.92th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.27% (0.00275) | 68.94th | v3 (v2023.03.01) |
| Apr 3, 2024 | 0.26% (0.00256) | 64.86th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.19% (0.00188) | 56.14th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.20% (0.00197) | 56.50th | v3 (v2023.03.01) |
| May 8, 2023 | 0.15% (0.00154) | 50.28th | v3 (v2023.03.01) |
| Mar 25, 2023 | 0.20% (0.00197) | 55.94th | v3 (v2023.03.01) |
| Mar 17, 2023 | 0.25% (0.00250) | 61.20th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.22% (0.00219) | 58.04th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.69% (0.02686) | 82.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.69% (0.02686) | 81.17th | v2 (v2022.01.01) |
| Feb 4, 2022 | 24.56% (0.24563) | 95.26th | v2 (v2022.01.01) |
| Feb 3, 2022 | 13.92% (0.13924) | 89.41th | v1 |
| Jan 6, 2022 | 13.92% (0.13924) | 89.29th | v1 |
| Sep 1, 2021 | 3.48% (0.03480) | 82.00th | v1 |
| Apr 14, 2021 | 3.48% (0.03480) | 0.00th | v1 |
References (29)
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00048.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00052.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00053.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00025.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00001.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/22/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/23/5 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11068 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1709697 Issue Tracking
- https://github.com/advisories/GHSA-qxcg-xjjg-66mj Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2019-11068.yml
- https://github.com/sparklemotion/nokogiri/blob/f7aa3b0b29d6fe5fafe93dacd9b96b6b3d16b7ec/CHANGELOG.md?plain=1#L826
- https://github.com/sparklemotion/nokogiri/commit/fe034aedcc59b566740567d621843731686676b9
- https://github.com/sparklemotion/nokogiri/issues/1892
- https://github.com/sparklemotion/nokogiri/pull/1898
- https://gitlab.gnome.org/GNOME/libxslt/commit/e03553605b45c88f0b4b2980adfbbb8f6fca2fd6 x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/04/msg00016.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36TEYN37XCCKN2XUMRTBBW67BPNMSW4K vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCOAX2IHUMKCM3ILHTMGLHCDSBTLP2JU vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SK4YNISS22MJY22YX5I6V2U63QZAUEHA vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36TEYN37XCCKN2XUMRTBBW67BPNMSW4K
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCOAX2IHUMKCM3ILHTMGLHCDSBTLP2JU
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SK4YNISS22MJY22YX5I6V2U63QZAUEHA
- https://nvd.nist.gov/vuln/detail/CVE-2019-11068
- https://security.netapp.com/advisory/ntap-20191017-0001 x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/3947-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3947-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11068
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.