CVE-2025-32415

ADVISORY - nist

Summary

In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.

EPSS Score: 0.00028 (0.073)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Out-of-bounds Read

Improper Validation of Specified Quantity in Input

ADVISORY - redhat

Out-of-bounds Read


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in