CVE-2025-59777

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:libmicrohttpd:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:46

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de desreferencia de puntero NULL existe en GNU libmicrohttpd v1.0.2 y anteriores. La vulnerabilidad fue corregida en el commit ff13abc en la rama master del repositorio Git de libmicrohttpd, después de la etiqueta v1.0.2. Un paquete especialmente diseñado enviado por un atacante podría causar una condición de denegación de servicio (DoS).

14 Nov 2025, 18:07

Type Values Removed Values Added
CPE cpe:2.3:a:gnu:libmicrohttpd:*:*:*:*:*:*:*:*
References () https://git.gnunet.org/libmicrohttpd.git/commit/?id=ff13abc1c1d7d2b30d69d5c0bd4a237e1801c50b - () https://git.gnunet.org/libmicrohttpd.git/commit/?id=ff13abc1c1d7d2b30d69d5c0bd4a237e1801c50b - Patch
References () https://jvn.jp/en/jp/JVN76719218/ - () https://jvn.jp/en/jp/JVN76719218/ - Third Party Advisory
References () https://www.gnu.org/software/libmicrohttpd/ - () https://www.gnu.org/software/libmicrohttpd/ - Product
First Time Gnu libmicrohttpd
Gnu

10 Nov 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-10 05:15

Updated : 2026-06-17 09:46


NVD link : CVE-2025-59777

Mitre link : CVE-2025-59777

CVE.ORG link : CVE-2025-59777


JSON object : View

Products Affected

gnu

  • libmicrohttpd
CWE
CWE-476

NULL Pointer Dereference