CVE-2025-25341: Libxmljs Project Libxmljs

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_ref and entity_decl nodes causes a segmentation fault, potentially leading to a denial-of-service (DoS).

Affected products

Published 2025-12-26. Last modified 2026-06-17.