CVE-2025-24855

HIGH

libxslt < 1.1.43 - Use-After-Free in XPath Context Handling

Title source: llm
STIX 2.1

Description

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0032
EPSS Percentile 24.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (1)
xmlsoft/libxslt < 1.1.43
Published Mar 14, 2025
Tracked Since Feb 18, 2026