CVE-2025-49795: Gnome LIBXML2

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.

Affected products

  • Gnome LIBXML2: from 2.10.0, before 2.14.5 (fixed in 2.14.5)
  • Red Hat Red Hat Enterprise Linux 10: before 0:2.12.5-7.el10_0 (fixed in 0:2.12.5-7.el10_0)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Hardened Images: before 2.15.2-0.3.hum1 (fixed in 2.15.2-0.3.hum1)
  • Siemens Ruggedcom RST2428P: before V4.0 (fixed in V4.0)

Published 2025-06-16. Last modified 2026-09-18.