CVE-2019-11068: Critical severity Xmlsoft Libxslt vulnerability
Last updated 25 August 2025
Other sources
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-11068?
CVE-2019-11068 is a vulnerability in libxslt through version 1.1.33 that allows bypass of a protection mechanism.
How severe is CVE-2019-11068?
CVE-2019-11068 has a severity rating of 9.8 (critical).
How does CVE-2019-11068 affect libxslt?
CVE-2019-11068 affects libxslt versions 1.1.32-2.2~deb10u1, 1.1.32-2.2~deb10u2, 1.1.34-4+deb11u1, and 1.1.35-1.
What is the remedy for CVE-2019-11068 on Debian and Ubuntu systems?
On Debian, the remedy for CVE-2019-11068 is to update libxslt to version 1.1.34-4+deb11u1 or later. On Ubuntu, the remedy depends on the specific version you are using, refer to the relevant security notice for detailed instructions.
Where can I find more information about CVE-2019-11068?
You can find more information about CVE-2019-11068 in the CVE entry and the relevant Ubuntu security notices.