Vulnerability Description
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xmlsoft | Libxslt | < 1.1.43 |
Related Weaknesses (CWE)
References
- https://gitlab.gnome.org/GNOME/libxslt/-/issues/128ExploitIssue TrackingVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/03/msg00015.html
FAQ
What is CVE-2025-24855?
CVE-2025-24855 is a vulnerability with a CVSS score of 7.8 (HIGH). numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsl...
How severe is CVE-2025-24855?
CVE-2025-24855 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24855?
Check the references section above for vendor advisories and patch information. Affected products include: Xmlsoft Libxslt.