PT-2025-41849 · Libxslt+3 · Libxslt+3

Published

2025-07-23

·

Updated

2026-03-27

·

CVE-2025-11731

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions libxslt (affected versions not specified)
Description A flaw exists in the exsltFuncResultComp() function of libxslt, which processes EXSLT <func:result> elements during stylesheet parsing. The issue stems from incorrect type handling, where the function may incorrectly interpret an XML document node as an XML element node, leading to a type confusion. This can result in unexpected memory reads and potential application crashes. While exploitation is considered difficult, the flaw could lead to application instability or denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Type Confusion

Weakness Enumeration

Related Identifiers

AZL-70550
AZL-70601
BDU:2026-02739
CVE-2025-11731
ECHO-C04A-8EBF-D378
OESA-2026-1724
OESA-2026-1725
OESA-2026-1726
OESA-2026-1727
OESA-2026-1728
OPENSUSE-SU-2025:15641-1
OPENSUSE-SU-2025:20050-1
RHSA-2026:11015
SUSE-SU-2025:20892-1
SUSE-SU-2025:20897-1
SUSE-SU-2025:21008-1
SUSE-SU-2025:21031-1
SUSE-SU-2025:3743-1
SUSE-SU-2025:3778-1
SUSE-SU-2025:3875-1
SUSE-SU-2025_3743-1
SUSE-SU-2025_3778-1
SUSE-SU-2026:0603-1

Affected Products

Debian
Red Os
Suse
Libxslt