CVE-2019-11023: Graphviz

High severity, CVSS 8.8. EPSS: 4.9% chance of exploitation in the next 30 days.

The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.

Affected products

  • Graphviz Graphviz: version 2.39.20160612.1140 only

Published 2019-04-08. Last modified 2026-06-17.