A double free in the XSLT show_index function has been identified in Hiawatha web server version 10.8.2 through 11.7. This vulnerability allows an unauthenticated attacker to corrupt data, which may lead to arbitrary code execution.
https://kb.cert.org/vuls/id/461364
Source: Mitre, NVD
Published: 2025-09-09