/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-24855

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-24855

Severity

7.8

High

CVSS V3

Description

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing