CVE-2025-25341

A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_ref and entity_decl nodes causes a segmentation fault, potentially leading to a denial-of-service (DoS).
References
Link Resource
https://github.com/libxmljs/libxmljs/issues/667 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:libxmljs_project:libxmljs:1.0.11:*:*:*:*:node.js:*:*

History

31 Dec 2025, 21:37

Type Values Removed Values Added
CPE cpe:2.3:a:libxmljs_project:libxmljs:1.0.11:*:*:*:*:node.js:*:*
References () https://github.com/libxmljs/libxmljs/issues/667 - () https://github.com/libxmljs/libxmljs/issues/667 - Exploit, Issue Tracking, Third Party Advisory
First Time Libxmljs Project
Libxmljs Project libxmljs

26 Dec 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-400

26 Dec 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-26 15:15

Updated : 2025-12-31 21:37


NVD link : CVE-2025-25341

Mitre link : CVE-2025-25341

CVE.ORG link : CVE-2025-25341


JSON object : View

Products Affected

libxmljs_project

  • libxmljs
CWE
CWE-400

Uncontrolled Resource Consumption