CVE-2025-24855

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 14, 2025
CWE ID 416

Summary

CVE-2025-24855 is a vulnerability affecting libxslt's numbers.c module before version 1.1.43. In this issue, an XPath context node can be modified but never restored during nested XPath evaluations. This leads to a use-after-free condition in functions such as xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal. An attacker could exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share