[UPDATE] [hoch] libxml2: Mehrere Schwachstellen ermöglichen Denial of Service
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in libxml2 ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht näher beschriebene Auswirkungen zu erzielen.
CSIRTS triage
- What
- Multiple vulnerabilities allow remote attackers to cause denial-of-service or achieve unspecified impact through XML processing.
- Who is affected
- Applications and systems using affected versions of libxml2 library.
- Urgency
- High priority; remote attack vector and potential for unspecified impact.
- Action
- Update libxml2 to a patched version addressing CVE-2025-49794, CVE-2025-49795, CVE-2025-49796, and CVE-2025-6021.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch libxml2
Get an email when a new libxml2 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1312
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-497940.78% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-497950.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 44% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2025-497961.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2025-60211.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 70% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-49794 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-49795 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-49796 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-6021 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] Oracle Java SE: Mehrere Schwachstellencert-bund
- criticalexploited[UPDATE] [critical] Oracle Fusion Middleware: Multiple Vulnerabilitiescert-bund
- high[UPDATE] [high] Dell PowerProtect Data Domain OS: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Dell PowerProtect Data Domain: Multiple vulnerabilitiescert-bund
- criticalSiemens SINEC OScisa
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen2026-09-15
- high[NEU] [hoch] MISP: Mehrere Schwachstellen2026-09-15
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service oder unspezifischer Angri…2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff2026-09-15