CVE-2025-32415
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 17, 2025
Updated: Apr 23, 2025
CWE ID 125
CWE ID 1284
Summary
CVE-2025-32415 is a heap-based buffer under-read vulnerability affecting libxml2 before version 2.13.8 and 2.14.x before 2.14.2. This issue lies in the xmlSchemaIDCFillNodeTables function of xmlschemas.c. A maliciously crafted XML document or schema can be used to exploit this vulnerability, potentially leading to arbitrary code execution or memory corruption. Successful exploitation requires the validation of the malicious input against certain identity constraints or the use of a crafted XML schema.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- XMLSoft Libxml 2
- libxml2
Affected Vendors
- GNOME Project
- Xmlsoft