CVE-2025-24855 | Xmlsoft libxslt up to 1.1.42 numbers.c use after free (Issue 128 / EUVD-2025-7659)
A vulnerability was found in Xmlsoft libxslt up to 1.1.42. It has been declared as critical. This impacts the function xsltNumberFormatGetValue/xsltEvalXPathPredicate/xsltEvalXPathStringNs/xsltComputeSortResultInternal of the file numbers.c. Executing manipulation can lead to use after free.
The identification of this vulnerability is CVE-2025-24855. The attack can only be executed locally. There is no exploit available.
It is recommended to upgrade the affected component.