Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-578

JLSEC-2026-578

JLSEC Published
Modified
Affected Packages
XSLT_jll < 1.1.34+0
Aliases / Upstream
CVE-2019-13117

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

References