FlawAtlas
Search the atlas
CVE-2019-11068 Critical

Nokogiri vulnerable to libxslt protection mechanism bypass

A dependency of Nokogiri, libxslt through 1.1.33 allows bypass of a protection mechanism because callers of `xsltCheckRead` and `xsltCheckWrite` permit access even upon receiving a `-1` error code. `xsltCheckRead` can return `-1` for a crafted URL that is not actually invalid and is subsequently loaded.

Exploit probability 5.1%
Published May 13, 2022
Required by Not available
Last source change June 9, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

90 explicit affected versions

RubyGems nokogiri

112 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-qxcg-xjjg-66mj

A dependency of Nokogiri, libxslt through 1.1.33 allows bypass of a protection mechanism because callers of `xsltCheckRead` and `xsltCheckWrite` permit access even upon receiving a `-1` error code. `xsltCheckRead` can return `-1` for a crafted URL that is not actually invalid and is subsequently loaded.

View original source
Open Source Vulnerabilities CVE-2019-11068

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

View original source

05 / REFERENCES

Further evidence