ThreatCluster

Multiple CVEs Identified in libxslt Affecting XPath Evaluations

First seen 21 Feb 2026, 06:18 UTC Api.Msrc.Microsoft 41

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been reported in libxslt prior to version 1.1.43. CVE-2024-55549 involves a use-after vulnerability in xsltGetInheritedNsList, while CVE-2025-24855 is a use-after-free issue related to nested XPath evaluations. Both vulnerabilities were published on March 14, 2025, and could potentially impact applications utilizing this library.

Timeline

2025-03-14
CVE-2025-24855 published
2025-03-14
CVE-2024-55549 published
2026-02-18
Article published detailing CVE-2025-24855
2026-02-21
Article published detailing CVE-2024-55549