PT-2025-41849 · Libxslt+3 · Libxslt+3
CVE-2025-11731
·
Published
2025-07-23
·
Updated
2026-09-01
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
libxslt (affected versions not specified)
Description
A flaw exists in the
exsltFuncResultComp() function of libxslt, which processes EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may incorrectly treat an XML document node as a regular XML element node, leading to type confusion. This issue can result in unexpected memory reads, application instability, or a denial of service.Exploit
Fix
DoS
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Red Os
Suse
Libxslt