CVE-2019-9904: Graphviz
Medium severity, CVSS 6.5. EPSS: 2.7% chance of exploitation in the next 30 days.
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in lib\cgraph\subg.c.
Affected products
- Graphviz Graphviz: version 2.40.1 only
Published 2019-03-21. Last modified 2026-06-17.