CVE-2025-59777
published 2025-11-10CVE-2025-59777: NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of…
PriorityP345high8.7CVSS 4.0
AVNACLATNPRNUINVCNVINVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.42%
34.2th percentile
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libmicrohttpd | — | — |
| gnu | libmicrohttpd | < 2025-09-16 | 2025-09-16 |
| gnu_project | gnu_libbmicrohttpd | — | — |
| gnu_project | gnu_libbmicrohttpd | — | — |
| msrc | azl3_libmicrohttpd_0.9.77-3_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv8.7HIGH
vendor_debian8.7LOW
vendor_redhat8.7HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the
vendor_msrc·2025-11-11·CVSS 7.5
CVE-2025-59777 [HIGH] CWE-476 NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
Mariner: Mariner
jpcert: jpcert
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
libmicrohttpd: GNU libmicrohttpd null pointer dereference
vendor_redhat·2025-11-10·CVSS 8.7
CVE-2025-59777 [HIGH] CWE-476 libmicrohttpd: GNU libmicrohttpd null pointer dereference
libmicrohttpd: GNU libmicrohttpd null pointer dereference
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
A null pointer dereference vector has been discovered in GNU libmicrohttpd. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) in the application using libmicrohttpd.
Statement: The availability impact of this flaw is limited to applications using libmicrohttpd. Red Hat host operating systems are not at risk.
Mitigation: Mitigation for this issue is either not available or the currently avail
Debian
CVE-2025-59777: libmicrohttpd - NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and ea...
vendor_debian·2025·CVSS 8.7
CVE-2025-59777 [HIGH] CVE-2025-59777: libmicrohttpd - NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and ea...
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-f6rc-8xc8-gmfm: NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1
ghsa_unreviewed·2025-11-10
CVE-2025-59777 [HIGH] CWE-476 GHSA-f6rc-8xc8-gmfm: NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
OSV
CVE-2025-59777: NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1
osv·2025-11-10·CVSS 8.7
CVE-2025-59777 [HIGH] CVE-2025-59777: NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-59777 mingw-libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-42]
bugzilla·2025-11-10·CVSS 8.7
CVE-2025-59777 [HIGH] CVE-2025-59777 mingw-libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-42]
CVE-2025-59777 mingw-libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all b
Bugzilla
CVE-2025-59777 proxysql: GNU libmicrohttpd null pointer dereference [epel-8]
bugzilla·2025-11-10·CVSS 8.7
CVE-2025-59777 [HIGH] CVE-2025-59777 proxysql: GNU libmicrohttpd null pointer dereference [epel-8]
CVE-2025-59777 proxysql: GNU libmicrohttpd null pointer dereference [epel-8]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
---
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
Bugzilla
CVE-2025-59777 proxysql: GNU libmicrohttpd null pointer dereference [epel-9]
bugzilla·2025-11-10·CVSS 8.7
CVE-2025-59777 [HIGH] CVE-2025-59777 proxysql: GNU libmicrohttpd null pointer dereference [epel-9]
CVE-2025-59777 proxysql: GNU libmicrohttpd null pointer dereference [epel-9]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
---
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
Bugzilla
CVE-2025-59777 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-43]
bugzilla·2025-11-10·CVSS 8.7
CVE-2025-59777 [HIGH] CVE-2025-59777 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-43]
CVE-2025-59777 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-2026-aef0e41835 (libmicrohttpd-1.0.3-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-aef0e41835
---
FEDORA-2026-65a08d1312 (libmicrohtt
Bugzilla
CVE-2025-59777 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-42]
bugzilla·2025-11-10·CVSS 8.7
CVE-2025-59777 [HIGH] CVE-2025-59777 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-42]
CVE-2025-59777 libmicrohttpd: GNU libmicrohttpd null pointer dereference [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-2026-65a08d1312 (libmicrohttpd-1.0.3-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-65a08d1312
---
FEDORA-2026-7a0641ca41 (libmicrohtt
Bugzilla
CVE-2025-59777 proxysql: GNU libmicrohttpd null pointer dereference [fedora-42]
bugzilla·2025-11-10·CVSS 8.7
CVE-2025-59777 [HIGH] CVE-2025-59777 proxysql: GNU libmicrohttpd null pointer dereference [fedora-42]
CVE-2025-59777 proxysql: GNU libmicrohttpd null pointer dereference [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports
2025-11-10
Published