Back to Database
Status published
High
CVE-2025-49795
Libxml: null pointer dereference leads to denial of service (dos)
Vulnerability Description
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-49795
Credits & Attribution
No credits recorded in the NVD database.
References
- https://access.redhat.com/errata/RHSA-2025:10630
- https://access.redhat.com/errata/RHSA-2025:19020
- https://access.redhat.com/errata/RHSA-2026:7519
- https://access.redhat.com/security/cve/CVE-2025-49795
- https://bugzilla.redhat.com/show_bug.cgi?id=2372379
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/932
More from GNOME
View All →CVE-2025-7425
Libxslt: libxml2: heap use-after-free in libxslt caused by atype corruption in xmlattrptr
High
7.8
CVE-2025-7424
Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes
High
7.5
CVE-2025-14512
Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
Medium
6.5
CVE-2025-14087
Glib: glib: buffer underflow in gvariant parser leads to heap corruption
Medium
5.6
CVE-2025-12105
Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion
High
7.5
Affected Vendor
GNOME
View all reports →Affected Software
libxml2, Red Hat Enterprise Linux 10, Red Hat JBoss Core Services 2.4.62.SP2, Red Hat Hardened Images, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Vulnerable Versions:
2.10.0, 0:2.12.5-7.el10_0, 2.15.2-0.3.hum1
Timeline
Official Publish:
June 16th, 2025
Last Modified:
July 7th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.