Tools AI-Found Vulnerability Register aifv-0017
Register entry
libxslt type confusion in exsltFuncResultComp, found by Google Big Sleep
- CVE
- CVE-2025-11731
- Project
- libxslt
- Component
- exsltFuncResultComp
- Finder
- Google Big Sleep
- Autonomy
- agent finds and reproduces; a human expert reviews before reporting
- Evidence tier
- Credits array names the finder
- Assigner
- Red Hat
- Severity
- 3.1 Low (CVSS 3.1)
- Bounty
- None published
- Confidence
- CONFIRMED
What happened
A type confusion in libxslt before 1.1.44, assigned by Red Hat with a Big Sleep acknowledgement in the credits, one of two 2026-era Big Sleep records that reach the corpus through a downstream distributor rather than Google as CNA.
Credit as recorded: Red Hat would like to thank Google Big Sleep for reporting this issue.. Date basis: datePublic.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
On YFarmX
- Reference pageyfarmx.com/ai/security/big-sleep/
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026