CVE-2025-49795
GNOME libxml2, Red Hat Enterprise Linux 10, Red Hat JBoss Core Services 2.4.62.SP2
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.
- CVSS
- 7.5
- EPSS
- 0.47% 38.6% percentile
- CISA KEV
- Not listed
- Published
- 2025.06.17