---
id: CVE-2025-62689
title: >-
  NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and
  earlier
summary: >-
  NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and
  earlier. The vulnerability was fixed in commit ff13abc on the master branch of
  the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted
  pack…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-122
vendor: gnu
product: libmicrohttpd
affected:
  - libmicrohttpd < 1.0.3
patched:
  - libmicrohttpd 1.0.3
published: '2025-11-10'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T00:45:39.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62689'
references:
  - url: >-
      https://git.gnunet.org/libmicrohttpd.git/commit/?id=ff13abc1c1d7d2b30d69d5c0bd4a237e1801c50b
    label: vultures@jpcert.or.jp
  - url: 'https://jvn.jp/en/jp/JVN76719218/'
    label: vultures@jpcert.or.jp
  - url: 'https://www.gnu.org/software/libmicrohttpd/'
    label: vultures@jpcert.or.jp
tags:
  - nvd
epss: 0.00431
epssPercentile: 0.35341
ingestedAt: '2026-10-08T01:01:40.723Z'
---

## Overview

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.

## Affected

- `libmicrohttpd < 1.0.3`

## Remediation

Upgrade past the affected range:

- `libmicrohttpd 1.0.3`
