{"id":"CVE-2025-49795","summary":"Libxml: null pointer dereference leads to denial of service (dos)","details":"A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.","modified":"2026-08-12T03:51:15.647751070Z","published":"2025-06-16T15:19:29.871Z","related":["ALSA-2025:10630","SUSE-SU-2025:02260-1","SUSE-SU-2025:02314-1","SUSE-SU-2025:20564-1","SUSE-SU-2025:20607-1","openSUSE-SU-2025:15321-1"],"database_specific":{"cwe_ids":["CWE-825"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49795.json","cna_assigner":"redhat"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://catalog.redhat.com/software/containers/"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-253495.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:10630"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:19020"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:7519"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-49795"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49795.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49795"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2372379"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/libxml2/-/issues/932"},{"type":"PACKAGE","url":"https://gitlab.gnome.org/GNOME/libxml2/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/libxml2","events":[{"introduced":"ae383bdb74523ddaf831d7db0690173c25e483b3"},{"fixed":"74f3154320df8950eceae4951975cc9dfc3a254d"}],"database_specific":{"extracted_events":[{"introduced":"2.10.0"},{"fixed":"2.14.5"}],"source":"AFFECTED_FIELD"}}],"versions":["v2.14.4","v2.14.3","v2.14.2","v2.14.1","v2.14.0","v2.13.0","v2.12.0","v2.11.0","v2.10.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-49795.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}