/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-q7mp-f8p4-432r

Published

Last updated

https://images.chainguard.dev/security/CGA-q7mp-f8p4-432r
Package

gitlab-rails-ee-fips-17.8

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • GHSA-mrxw-mxhj-p664

Severity

Unknown

Summary

Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs

Description

Summary

Nokogiri v1.18.4 upgrades its dependency libxslt to v1.1.43.

libxslt v1.1.43 resolves:

  • CVE-2025-24855: Fix use-after-free of XPath context node
  • CVE-2024-55549: Fix UAF related to excluded namespaces

Impact

CVE-2025-24855

CVE-2024-55549

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs