CVE-2025-49796Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-15); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-15: 1Mentions · 2026-07-08: 1Technical Details · 2026-04-15: 1Technical Details · 2026-07-08: 104-1507-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2025-49796: Memory Corruption Chain in Siemens SINEC OS on RUGGEDCOM RST2428P https://breachspider.com/intel/2026-07-08-cve-2025-49796-memory-corruption-chain-in-siemens-sinec-os-o #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The tweet announces a CVE-2025-49796 analysis describing a memory corruption chain in Siemens SINEC OS on a Ruggedcom device, without providing PoC, exploit details, patch information, or evidence of active exploitation.

    01041176
    2.3K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-49796: Libxml: type confusion leads to ... Memory corruption in libxml2's sch:name parsing hits CVSS 9.1 - trivial XML crafting can crash any app parsing schemas,... https://zerodaysignal.com/vulnerability/CVE-2025-49796 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses a type‑confusion memory corruption vulnerability (CVE‑2025‑49796) in libxml2 with CVSS 9.1, noting trivial XML crafting can crash schema‑parsing applications; no PoC, exploit, or patch is referenced.

    00000255
    218 followersView on X

Explore more