A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution.
References
| Link | Resource |
|---|---|
| https://gitlab.com/hsleisink/hiawatha/-/blame/master/src/xslt.c?ref_type=heads#L675 | Release Notes |
Configurations
History
No history.
Information
Published : 2026-01-26 18:16
Updated : 2026-02-13 15:21
NVD link : CVE-2025-57785
Mitre link : CVE-2025-57785
CVE.ORG link : CVE-2025-57785
JSON object : View
Products Affected
hiawatha.leisink
- hiawatha_webserver
CWE
CWE-415
Double Free
