DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CVE-2025-24855

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-24855

Severity

7.8

High

CVSS V3

Description

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-24855

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing