CVE-2025-24855 | Xmlsoft libxslt up to 1.1.42 numbers.c use after free (Issue 128)
A vulnerability was found in Xmlsoft libxslt up to 1.1.42 and classified as critical. This issue affects the function xsltNumberFormatGetValue/xsltEvalXPathPredicate/xsltEvalXPathStringNs/xsltComputeSortResultInternal of the file numbers.c. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2025-24855. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.