CVE-2025-11731

A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service.
Configurations

No configuration.

History

15 Oct 2025, 18:15

Type Values Removed Values Added
References
  • () https://gitlab.gnome.org/GNOME/libxslt/-/merge_requests/78 -

14 Oct 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 06:15

Updated : 2025-10-15 18:15


NVD link : CVE-2025-11731

Mitre link : CVE-2025-11731

CVE.ORG link : CVE-2025-11731


JSON object : View

Products Affected

No product.

CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')