CVE-2025-32415

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 17, 2025
Updated: Apr 23, 2025
CWE ID 125
CWE ID 1284

Summary

CVE-2025-32415 is a heap-based buffer under-read vulnerability affecting libxml2 before version 2.13.8 and 2.14.x before 2.14.2. This issue lies in the xmlSchemaIDCFillNodeTables function of xmlschemas.c. A maliciously crafted XML document or schema can be used to exploit this vulnerability, potentially leading to arbitrary code execution or memory corruption. Successful exploitation requires the validation of the malicious input against certain identity constraints or the use of a crafted XML schema.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • XMLSoft Libxml 2
  • libxml2

Affected Vendors

  • GNOME Project
  • Xmlsoft