CVE-2025-49796
Executive Summary
CVE-2025-49796 exposes a memory corruption flaw in libxml2 triggered by specially crafted sch:name elements in XML. An attacker can supply malicious XML to cause libxml to crash, leading to denial‑of‑service or undefined behavior from corrupted memory. The issue is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 9.1 (CRITICAL) - Published: 2025-06-16T16:15:19.370 - Last Modified: 2026-09-28T02:17:16.583
Original Description: A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.
"Great talent finds happiness in execution."
— Johann Wolfgang von Goethe