Type Confusion Vulnerability in libxslt for Red Hat Products
CVE-2025-11731

3.1LOW

What is CVE-2025-11731?

A flaw exists in the exsltFuncResultComp() function of libxslt, responsible for processing EXSLT func:result elements during the parsing of stylesheets. The improper handling of types can lead to the misinterpretation of an XML document node as a standard XML element node. This type confusion could result in unexpected memory reads, potentially causing application instability, crashes, or denial of service. While the exploitation of this flaw is challenging, its implications could severely impact applications relying on libxslt for XML processing.

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11731 : Type Confusion Vulnerability in libxslt for Red Hat Products