CVE-2025-49795
published 2025-06-16CVE-2025-49795: A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.47%
38.0th percentile
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libxml2 | — | — |
| gnome | libxml2 | >= 2.10.0 < 2.14.5 | 2.14.5 |
| msrc | azl3_libxml2_2.11.5-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_libxml2_2.11.5-7_on_azure_linux_3.0 | — | — |
| msrc | cbl2_libxml2_2.10.4-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_libxml2_2.10.4-9_on_cbl_mariner_2.0 | — | — |
| nokogiri | nokogiri | >= 0 < 1.18.9 | 1.18.9 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa9.1CRITICAL
osv9.1CRITICAL
vendor_debian7.5LOW
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libxml: Null pointer dereference leads to Denial of service (DoS)
vendor_redhat·2025-06-11·CVSS 7.5
CVE-2025-49795 [HIGH] CWE-825 libxml: Null pointer dereference leads to Denial of service (DoS)
libxml: Null pointer dereference leads to Denial of service (DoS)
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
Statement: This vulnerability marked as Important rather than Moderate due to its triggerability through untrusted input and impact on availability in a widely-used XML processing library like libxml2, which is often embedded in system-level and server-side applications. Although it is "just" a NULL pointer dereference—
Microsoft
Libxml: null pointer dereference leads to denial of service (dos)
vendor_msrc·2025-06-10·CVSS 7.5
CVE-2025-49795 [HIGH] CWE-825 Libxml: null pointer dereference leads to denial of service (dos)
Libxml: null pointer dereference leads to denial of service (dos)
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: h
Debian
CVE-2025-49795: libxml2 - A NULL pointer dereference vulnerability was found in libxml2 when processing XP...
vendor_debian·2025·CVSS 7.5
CVE-2025-49795 [HIGH] CVE-2025-49795: libxml2 - A NULL pointer dereference vulnerability was found in libxml2 when processing XP...
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
Nokogiri patches vendored libxml2 to resolve multiple CVEs
osv·2025-07-21·CVSS 9.1
CVE-2025-6021 [CRITICAL] Nokogiri patches vendored libxml2 to resolve multiple CVEs
Nokogiri patches vendored libxml2 to resolve multiple CVEs
## Summary
Nokogiri v1.18.9 patches the vendored libxml2 to address CVE-2025-6021, CVE-2025-6170, CVE-2025-49794, CVE-2025-49795, and CVE-2025-49796.
## Impact and severity
### CVE-2025-6021
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
NVD claims a severity of 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Fixed by applying https://gitlab.gnome.org/GNOME/libxml2/-/commit/17d950ae
### CVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user input
GHSA
Nokogiri patches vendored libxml2 to resolve multiple CVEs
ghsa·2025-07-21·CVSS 9.1
CVE-2025-6021 [CRITICAL] Nokogiri patches vendored libxml2 to resolve multiple CVEs
Nokogiri patches vendored libxml2 to resolve multiple CVEs
## Summary
Nokogiri v1.18.9 patches the vendored libxml2 to address CVE-2025-6021, CVE-2025-6170, CVE-2025-49794, CVE-2025-49795, and CVE-2025-49796.
## Impact and severity
### CVE-2025-6021
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
NVD claims a severity of 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Fixed by applying https://gitlab.gnome.org/GNOME/libxml2/-/commit/17d950ae
### CVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user input
OSV
CVE-2025-49795: A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions
osv·2025-06-16·CVSS 7.5
CVE-2025-49795 [HIGH] CVE-2025-49795: A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
GHSA
GHSA-gg7j-w83p-fxr9: A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions
ghsa_unreviewed·2025-06-16
CVE-2025-49795 [HIGH] CWE-825 GHSA-gg7j-w83p-fxr9: A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-49795 libxml2: NULL pointer dereference in XPath expression processing [fedora-43]
bugzilla·2026-04-15·CVSS 7.5
CVE-2025-49795 [HIGH] CVE-2025-49795 libxml2: NULL pointer dereference in XPath expression processing [fedora-43]
CVE-2025-49795 libxml2: NULL pointer dereference in XPath expression processing [fedora-43]
libxml2-2.12.10-5.fc43 is affected by CVE-2025-49795.
Affected versions: libxml2 >= 2.10.0 (vulnerability introduced in 2.10.0)
Fixed in: libxml2 2.14.5
Upstream fix: https://gitlab.gnome.org/GNOME/libxml2/-/commit/499bcb78ab389f60c2fd634ce410d4bb85c18765
available version in fedora repository libxml2-2.12.10-5.fc43
Did not see that this CVE is fixed in any patch.
Reproducible: Always
Bugzilla
CVE-2025-49795 mingw-libxml2: Null pointer dereference leads to Denial of service (DoS) [fedora-42]
bugzilla·2025-06-12·CVSS 7.5
CVE-2025-49795 [HIGH] CVE-2025-49795 mingw-libxml2: Null pointer dereference leads to Denial of service (DoS) [fedora-42]
CVE-2025-49795 mingw-libxml2: Null pointer dereference leads to Denial of service (DoS) [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2372379
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version
Bugzilla
CVE-2025-49795 libxml2: Null pointer dereference leads to Denial of service (DoS) [fedora-42]
bugzilla·2025-06-12·CVSS 7.5
CVE-2025-49795 [HIGH] CVE-2025-49795 libxml2: Null pointer dereference leads to Denial of service (DoS) [fedora-42]
CVE-2025-49795 libxml2: Null pointer dereference leads to Denial of service (DoS) [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2372379
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '
Bugzilla
CVE-2025-49795 libxml: Null pointer dereference leads to Denial of service (DoS)
bugzilla·2025-06-12·CVSS 7.5
CVE-2025-49795 [HIGH] CVE-2025-49795 libxml: Null pointer dereference leads to Denial of service (DoS)
CVE-2025-49795 libxml: Null pointer dereference leads to Denial of service (DoS)
A null pointer dereference vulnerability was discovered in the libxml2. The issue occurs in the xmlSchematronFormatReport function when processing incorrect XPath expressions in Schematron schema reports, leading to undefined behavior and potential crashes.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:10630 https://access.redhat.com/errata/RHSA-2025:10630
---
This issue has been addressed in the following products:
Red Hat JBoss Core Services 2.4.62.SP2
Via RHSA-2025:19020 https://access.redhat.com/errata/RHSA-2025:19020
https://access.redhat.com/errata/RHSA-2025:10630https://access.redhat.com/errata/RHSA-2025:19020https://access.redhat.com/errata/RHSA-2026:7519https://access.redhat.com/security/cve/CVE-2025-49795https://bugzilla.redhat.com/show_bug.cgi?id=2372379https://gitlab.gnome.org/GNOME/libxml2/-/issues/932https://cert-portal.siemens.com/productcert/html/ssa-253495.html
2025-06-16
Published