CVE-2025-24855
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 14, 2025
CWE ID 416
Summary
CVE-2025-24855 is a vulnerability affecting libxslt's numbers.c module before version 1.1.43. In this issue, an XPath context node can be modified but never restored during nested XPath evaluations. This leads to a use-after-free condition in functions such as xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal. An attacker could exploit this vulnerability to execute arbitrary code or cause a denial-of-service condition.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Xmlsoft Libxslt