CVE-2025-49794

Executive Summary

A use‑after‑free flaw in libxml2 triggers when parsing XPath elements that reference in an XML Schematron. A crafted XML document can cause the library to crash or exhibit undefined behavior, potentially leading to denial‑of‑service or other exploitation vectors. The vulnerability is not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 9.1 (CRITICAL) - Published: 2025-06-16T16:15:18.997 - Last Modified: 2026-09-28T02:17:15.060

Original Description: A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.

"This is the final test of a gentleman: his respect for those who can be of no possible value to him."

— William Lyon Phelps
Source: NVD