CVE-2025-24855
published 2025-03-14CVE-2025-24855: numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.32%
24.5th percentile
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.3_and_ipados | — | — |
| apple | ipados | — | — |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
| apple | tvos | — | — |
| apple | visionos | — | — |
| apple | watchos | — | — |
| debian | libxslt | < libxslt 1.1.35-1+deb12u1 (bookworm) | libxslt 1.1.35-1+deb12u1 (bookworm) |
| msrc | azl3_libxslt_1.1.39-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_libxslt_1.1.43-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libxslt_1.1.34-8_on_cbl_mariner_2.0 | — | — |
| nokogiri | nokogiri | >= 0 < 1.18.4 | 1.18.4 |
| xmlsoft | libxslt | < 1.1.43 | 1.1.43 |
| xmlsoft | libxslt | >= 0 < 1.1.34-4+deb11u2 | 1.1.34-4+deb11u2 |
| xmlsoft | libxslt | >= 0 < 1.1.35-1+deb12u1 | 1.1.35-1+deb12u1 |
| xmlsoft | libxslt | >= 0 < 1.1.35-1.2 | 1.1.35-1.2 |
| xmlsoft | libxslt | >= 0 < 1.1.35-1.2 | 1.1.35-1.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa7.8HIGH
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libxslt vulnerabilities
vendor_ubuntu·2025-09-30
CVE-2024-55549 Libxslt vulnerabilities
Title: Libxslt vulnerabilities
Summary: Several security issues were fixed in Libxslt.
Ivan Fratric discovered that Libxslt did not correctly handle certain
memory operations. An attacker could possibly use this issue to execute
arbitrary code or cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Java SE Risk Matrix: JavaFX (libxslt) — CVE-2025-24855
vendor_oracle·2025-07-15·CVSS 7.5
CVE-2025-24855 [HIGH] Oracle Oracle Java SE Risk Matrix: JavaFX (libxslt) — CVE-2025-24855
Oracle Oracle Java SE Risk Matrix: JavaFX (libxslt) vulnerability
CVE: CVE-2025-24855
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Ubuntu
Libxslt vulnerability
vendor_ubuntu·2025-03-20
CVE-2025-24855 Libxslt vulnerability
Title: Libxslt vulnerability
Summary: Libxslt could be made to crash or run programs if it opened a specially
crafted file.
Ivan Fratric discovered that Libxslt incorrectly handled certain memory
operations when handling documents. A remote attacker could use this issue
to cause Libxslt to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libxslt: Use-After-Free in libxslt numbers.c
vendor_redhat·2025-03-14·CVSS 7.8
CVE-2025-24855 [HIGH] CWE-416 libxslt: Use-After-Free in libxslt numbers.c
libxslt: Use-After-Free in libxslt numbers.c
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
A flaw was found in libxslt numbers.c. This vulnerability allows a use-after-free, potentially leading to memory corruption or code execution via nested XPath evaluations where an XPath context node can be modified but not restored.
Statement: The use-after-free vulnerability in libxslt marked as a high severity rather than moderate due to its potential impact on system integrity and availability. This flaw arises during nested XPath evaluations where the context node
Microsoft
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsl
vendor_msrc·2025-03-11·CVSS 7.8
CVE-2025-24855 [HIGH] CWE-416 numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsl
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more i
Apple
CVE-2025-24855: iOS 18.3 and iPadOS 18.3
vendor_apple·2025-01-27·CVSS 7.8
CVE-2025-24855 [HIGH] CVE-2025-24855: iOS 18.3 and iPadOS 18.3
Apple Security Update: About the security content of iOS 18.3 and iPadOS 18.3
Product: iOS 18.3 and iPadOS
Version: 18.3
CVE: CVE-2025-24855
Component: Libnotify
Impact: An app may be able to cause a denial-of-service
Description: An app could impersonate system notifications. Sensitive notifications now require restricted entitlements.
Apple
CVE-2025-24855: macOS Sequoia 15.3
vendor_apple·2025-01-27·CVSS 7.8
CVE-2025-24855 [HIGH] CVE-2025-24855: macOS Sequoia 15.3
Apple Security Update: About the security content of macOS Sequoia 15.3
Product: macOS Sequoia
Version: 15.3
CVE: CVE-2025-24855
Component: LaunchServices
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with improved redaction of sensitive information.
Apple
CVE-2025-24855: iPadOS 17.7.4
vendor_apple·2025-01-27·CVSS 7.8
CVE-2025-24855 [HIGH] CVE-2025-24855: iPadOS 17.7.4
Apple Security Update: About the security content of iPadOS 17.7.4
Product: iPadOS
Version: 17.7.4
CVE: CVE-2025-24855
Component: LaunchServices
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with improved redaction of sensitive information.
Apple
CVE-2025-24855: visionOS 2.3
vendor_apple·2025-01-27·CVSS 7.8
CVE-2025-24855 [HIGH] CVE-2025-24855: visionOS 2.3
Apple Security Update: About the security content of visionOS 2.3
Product: visionOS
Version: 2.3
CVE: CVE-2025-24855
Component: LaunchServices
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with improved redaction of sensitive information.
Apple
CVE-2025-24855: macOS Ventura 13.7.3
vendor_apple·2025-01-27·CVSS 7.8
CVE-2025-24855 [HIGH] CVE-2025-24855: macOS Ventura 13.7.3
Apple Security Update: About the security content of macOS Ventura 13.7.3
Product: macOS Ventura
Version: 13.7.3
CVE: CVE-2025-24855
Component: LaunchServices
Impact: An app may be able to bypass Privacy preferences
Description: An access issue was addressed with additional sandbox restrictions.
Apple
CVE-2025-24855: watchOS 11.3
vendor_apple·2025-01-27·CVSS 7.8
CVE-2025-24855 [HIGH] CVE-2025-24855: watchOS 11.3
Apple Security Update: About the security content of watchOS 11.3
Product: watchOS
Version: 11.3
CVE: CVE-2025-24855
Component: LaunchServices
Impact: An app may be able to fingerprint the user
Description: This issue was addressed with improved redaction of sensitive information.
Apple
CVE-2025-24855: macOS Sonoma 14.7.3
vendor_apple·2025-01-27·CVSS 7.8
CVE-2025-24855 [HIGH] CVE-2025-24855: macOS Sonoma 14.7.3
Apple Security Update: About the security content of macOS Sonoma 14.7.3
Product: macOS Sonoma
Version: 14.7.3
CVE: CVE-2025-24855
Component: LaunchServices
Impact: An app may be able to bypass Privacy preferences
Description: An access issue was addressed with additional sandbox restrictions.
Apple
CVE-2025-24855: tvOS 18.3
vendor_apple·2025-01-27·CVSS 7.8
CVE-2025-24855 [HIGH] CVE-2025-24855: tvOS 18.3
Apple Security Update: About the security content of tvOS 18.3
Product: tvOS
Version: 18.3
CVE: CVE-2025-24855
Component: Kernel
Impact: An app may be able to execute arbitrary code with kernel privileges
Description: A validation issue was addressed with improved logic.
Debian
CVE-2025-24855: libxslt - numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath...
vendor_debian·2025·CVSS 7.8
CVE-2025-24855 [HIGH] CVE-2025-24855: libxslt - numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath...
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
Scope: local
bookworm: resolved (fixed in 1.1.35-1+deb12u1)
bullseye: resolved (fixed in 1.1.34-4+deb11u2)
forky: resolved (fixed in 1.1.35-1.2)
sid: resolved (fixed in 1.1.35-1.2)
trixie: resolved (fixed in 1.1.35-1.2)
GHSA
GHSA-3cgj-v3m4-cgcq: numbers
ghsa_unreviewed·2025-03-14
CVE-2025-24855 [HIGH] CWE-416 GHSA-3cgj-v3m4-cgcq: numbers
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
OSV
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
osv·2025-03-14·CVSS 7.8
CVE-2025-24855 [HIGH] Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
## Summary
Nokogiri v1.18.4 upgrades its dependency libxslt to [v1.1.43](https://gitlab.gnome.org/GNOME/libxslt/-/releases/v1.1.43).
libxslt v1.1.43 resolves:
- CVE-2025-24855: Fix use-after-free of XPath context node
- CVE-2024-55549: Fix UAF related to excluded namespaces
## Impact
### CVE-2025-24855
- "Use-after-free due to xsltEvalXPathStringNs leaking xpathCtxt->node"
- MITRE has rated this 7.8 High CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
- Upstream report: https://gitlab.gnome.org/GNOME/libxslt/-/issues/128
- NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2025-24855
### CVE-2024-55549
- "Use-after-free related to excluded result prefixes"
- MITRE has rated this 7.8 High CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S
OSV
CVE-2025-24855: numbers
osv·2025-03-14·CVSS 7.8
CVE-2025-24855 [HIGH] CVE-2025-24855: numbers
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is related to xsltNumberFormatGetValue, xsltEvalXPathPredicate, xsltEvalXPathStringNs, and xsltComputeSortResultInternal.
GHSA
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
ghsa·2025-03-14·CVSS 7.8
CVE-2025-24855 [HIGH] CWE-1395 Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
Nokogiri updates packaged libxslt to v1.1.43 to resolve multiple CVEs
## Summary
Nokogiri v1.18.4 upgrades its dependency libxslt to [v1.1.43](https://gitlab.gnome.org/GNOME/libxslt/-/releases/v1.1.43).
libxslt v1.1.43 resolves:
- CVE-2025-24855: Fix use-after-free of XPath context node
- CVE-2024-55549: Fix UAF related to excluded namespaces
## Impact
### CVE-2025-24855
- "Use-after-free due to xsltEvalXPathStringNs leaking xpathCtxt->node"
- MITRE has rated this 7.8 High CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
- Upstream report: https://gitlab.gnome.org/GNOME/libxslt/-/issues/128
- NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2025-24855
### CVE-2024-55549
- "Use-after-free related to excluded result prefixes"
- MITRE has rated this 7.8 High CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-14
Published