CVE-2024-55549

Severity
7.8HIGH
EPSS
0.1%
top 84.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 14
Latest updateSep 30

Description

xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:HExploitability: 1.4 | Impact: 5.8

Affected Packages4 packages

CVEListV5xmlsoft/libxslt< 1.1.43
NVDxmlsoft/libxslt< 1.1.43
Debianlibxslt< 1.1.34-4+deb11u2+3
RubyGemsnokogiri< 1.18.4

🔴Vulnerability Details

5
GHSA
GHSA-g8fv-r98j-937r: xsltGetInheritedNsList in libxslt before 12025-03-14
CVEList
CVE-2024-55549: xsltGetInheritedNsList in libxslt before 12025-03-14
OSV
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs2025-03-14
OSV
CVE-2024-55549: xsltGetInheritedNsList in libxslt before 12025-03-14
GHSA
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs2025-03-14

📋Vendor Advisories

13
Ubuntu
Libxslt vulnerabilities2025-09-30
Ubuntu
Libxslt vulnerability2025-03-19
Red Hat
libxslt: Use-After-Free in libxslt (xsltGetInheritedNsList)2025-03-14
Microsoft
xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue2025-03-11
Apple
CVE-2024-55549: iOS 18.3 and iPadOS 18.32025-01-27
CVE-2024-55549 (HIGH CVSS 7.8) | xsltGetInheritedNsList in libxslt b | cvebase.io