Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-580

JLSEC-2026-580

JLSEC Published
Modified
Affected Packages
XSLT_jll < 1.1.34+0
Aliases / Upstream
CVE-2019-18197

In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.

References