CVE-2019-18604: AXODRAW2 Project AXODRAW2

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.

Affected products

Published 2019-10-29. Last modified 2026-06-17.