CVE-2025-7424Disclosure(redhat / enterprise_linux)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • libxslt
  • openshift_container_platform

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
enterprise_linuxlibxsltopenshift_container_platform

7 versions affected across 3 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-29: 1Technical Details · 2026-04-29: 104-29
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • AiSoloStudio@aisolostudio
    Disclosure

    WordPress系にCVSS 10.0のファイルアップロード脆弱性。libxsltの型混同(CVE-2025-7424)やSambaの権限昇格も更新されており、インフラ管理者は確認を。本日のCVE 200件まとめ #セキュリティ #CVE #脆弱性 https://tsumikasane.net/security/daily/2026-04-29/

    Post summary

    The post announces newly disclosed CVEs, notably CVE-2025-7424 with a CVSS 10.0 file upload vulnerability in WordPress, along with updates on libxslt type confusion and Samba privilege escalation, but offers no PoC, exploit, patch or evidence of active exploitation.

    00000596
    21 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
Appredhatopenshift_container_platform4.0--
Appxmlsoftlibxslt---

Explore more