BIT-java-min-2025-7425

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/java-min/BIT-java-min-2025-7425.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-java-min-2025-7425
Aliases
Published
2026-05-06T14:45:51.559Z
Modified
2026-05-13T12:15:39.397835Z
Summary
Libxslt: libxml2: heap use-after-free in libxslt caused by atype corruption in xmlattrptr
Details

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.

Database specific
{
    "cpes": [
        "cpe:2.3:a:bellsoft:libericajdk:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / java-min

Package

Name
java-min
Purl
pkg:bitnami/java-min

Severity

  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.0
Introduced
1.9.0
Fixed
8.0.481

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/java-min/BIT-java-min-2025-7425.json"