CVE-2025-57785

Severity CVSS v4.0:
Pending analysis
Type:
CWE-415 Double Free
Publication date:
26/01/2026
Last modified:
13/02/2026

Description

A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hiawatha.leisink:hiawatha_webserver:11.7:*:*:*:*:*:*:*