---
id: CVE-2025-7424
title: A flaw was found in the libxslt library
summary: >-
  A flaw was found in the libxslt library. The same memory field, psvi, is used
  for both stylesheet and input data, which can lead to type confusion during
  XML transformations. This vulnerability allows an attacker to crash the
  application…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-843
vendor: xmlsoft
product: libxslt
affected:
  - libxslt
  - openshift_container_platform = 4.0
  - enterprise_linux = 6.0
  - enterprise_linux = 7.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux = 10.0
published: '2025-07-10'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-7424'
references:
  - url: 'https://access.redhat.com/errata/RHBA-2025:12345'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:11015'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-7424'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2379228'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/libxslt/-/issues/139'
    label: secalert@redhat.com
  - url: 'http://seclists.org/fulldisclosure/2025/Aug/0'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/30'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/32'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/33'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/35'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/37'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2025/07/11/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2025/09/msg00024.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01238
epssPercentile: 0.67776
ingestedAt: '2026-06-29T13:24:34.390Z'
---

## Overview

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.

## Affected

- `libxslt`
- `openshift_container_platform = 4.0`
- `enterprise_linux = 6.0`
- `enterprise_linux = 7.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux = 10.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
