Libxslt Vulnerabilities: Unmaintained and Unfixed Security Risks
- Security vulnerabilities have been identified in libxml2 and libxslt, with two of three reported issues in libxslt now publicly disclosed.
- (CVE-2025-7424) concerns a type confusion vulnerability in libxslt affecting the interaction between stylesheet and source nodes within the xmlNode.psvi function.
- (CVE-2025-7425) details a heap-use-after-free vulnerability in libxslt's xmlFreeID function, triggered by corruption of the atype variable.
Libxslt Vulnerabilities Disclosed: Patches Await Maintainer
Table of Contents
– Updated August 29, 2025, 07:27:16 UTC
Overview
Security vulnerabilities have been identified in libxml2 and libxslt, with two of three reported issues in libxslt now publicly disclosed. These vulnerabilities, discovered by engineers at Apple and Google, currently lack applied patches due to the absence of a maintainer for the libxslt project.
Vulnerability Details
(CVE-2025-7424) concerns a type confusion vulnerability in libxslt affecting the interaction between stylesheet and source nodes within the xmlNode.psvi function. Further information is available on the GNOME GitLab issue tracker and Project ZeroS issue tracker.
(CVE-2025-7425) details a heap-use-after-free vulnerability in libxslt’s xmlFreeID function, triggered by corruption of the atype variable. Details can be found on the GNOME GitLab issue tracker and project Zero’s issue tracker.
Patch Status and Maintainership
While Apple and Google engineers have submitted proposed patches to the GNOME GitLab repository, these fixes have not been applied. This is directly attributable to the current lack of a maintainer for the libxslt project, preventing the integration of these critical security updates.
Impact and affected Systems
The impact of these vulnerabilities is currently being assessed. Systems utilizing libxslt are potentially at risk. Users are advised to monitor the GNOME Security Wiki for updates and potential workarounds.
