CVE-2025-6021High· 7.5▾ MidnightPoC availableA flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafte…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
1.1%
1.1% → 1.4%
Last analysed / modified upstream
Exploit / PoC code exists
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input.
libxml2 < 2.14.4jboss_core_servicesopenshift_container_platform = 4.12openshift_container_platform = 4.13openshift_container_platform = 4.14openshift_container_platform = 4.15openshift_container_platform = 4.16openshift_container_platform = 4.17openshift_container_platform = 4.18openshift_container_platform_for_arm64 = 4.13openshift_container_platform_for_arm64 = 4.14openshift_container_platform_for_arm64 = 4.15openshift_container_platform_for_arm64 = 4.16openshift_container_platform_for_arm64 = 4.17openshift_container_platform_for_arm64 = 4.18openshift_container_platform_for_ibm_z = 4.13openshift_container_platform_for_ibm_z = 4.14openshift_container_platform_for_ibm_z = 4.15openshift_container_platform_for_ibm_z = 4.16openshift_container_platform_for_ibm_z = 4.17openshift_container_platform_for_ibm_z = 4.18openshift_container_platform_for_linuxone = 4.13openshift_container_platform_for_linuxone = 4.14openshift_container_platform_for_linuxone = 4.15openshift_container_platform_for_linuxone = 4.16openshift_container_platform_for_linuxone = 4.17openshift_container_platform_for_linuxone = 4.18openshift_container_platform_for_power = 4.13openshift_container_platform_for_power = 4.14openshift_container_platform_for_power = 4.15openshift_container_platform_for_power = 4.16openshift_container_platform_for_power = 4.17openshift_container_platform_for_power = 4.18enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0enterprise_linux_eus = 8.4enterprise_linux_eus = 8.6enterprise_linux_eus = 8.8enterprise_linux_eus = 9.4enterprise_linux_eus = 9.6enterprise_linux_eus = 10.0enterprise_linux_for_arm_64 = 8.0_aarch64enterprise_linux_for_arm_64 = 9.0_aarch64enterprise_linux_for_arm_64 = 9.4_aarch64enterprise_linux_for_arm_64 = 10.0_aarch64enterprise_linux_for_arm_64_eus = 9.4_aarch64enterprise_linux_for_arm_64_eus = 9.6_aarch64enterprise_linux_for_arm_64_eus = 10.0_aarch64enterprise_linux_for_ibm_z_systems = 8.0_s390xenterprise_linux_for_ibm_z_systems = 9.4_s390xenterprise_linux_for_ibm_z_systems = 10.0_s390xenterprise_linux_for_ibm_z_systems_eus = 9.0_s390xenterprise_linux_for_ibm_z_systems_eus = 9.4_s390xenterprise_linux_for_ibm_z_systems_eus = 9.6_s390xenterprise_linux_for_ibm_z_systems_eus = 10.0_s390xenterprise_linux_for_power_little_endian = 8.0_ppc64leenterprise_linux_for_power_little_endian = 9.0_ppc64leenterprise_linux_for_power_little_endian = 10.0_ppc64leenterprise_linux_for_power_little_endian_eus = 9.4_ppc64leenterprise_linux_for_power_little_endian_eus = 9.6_ppc64leenterprise_linux_for_power_little_endian_eus = 10.0_ppc64leenterprise_linux_server = 7.0enterprise_linux_server_aus = 8.2enterprise_linux_server_aus = 8.4enterprise_linux_server_aus = 8.6enterprise_linux_server_aus = 9.2enterprise_linux_server_aus = 9.4enterprise_linux_server_aus = 9.6enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.4_ppc64leenterprise_linux_server_tus = 8.8in-vehicle_operating_system = 1.0Upgrade past the affected range:
libxml2 2.14.4Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-7425High· 7.8A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management
CVE-2025-49796Critical· 9.1A vulnerability was found in libxml2
CVE-2025-49795High· 7.5A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions
CVE-2025-49794Critical· 9.1A use-after-free vulnerability was found in libxml2
CVE-2026-86138Medium· 6.9In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
CVE-2026-76781Medium· 5.5A flaw was found in libxml2