CVE-2025-8732: Uncontrolled Recursion in libxml2
A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."
AI Analysis
Technical Summary
This vulnerability in libxml2's xmlParseSGMLCatalog function leads to uncontrolled recursion when parsing untrusted SGML catalogs. It requires local attacker privileges and does not involve user interaction or elevated privileges. The maintainer doubts the real-world impact due to the obsolescence of SGML catalogs and the requirement to use untrusted catalogs to trigger the issue. The CVSS 4.8 score reflects limited attack vector and impact. No patch or vendor advisory has been provided.
Potential Impact
The vulnerability could cause uncontrolled recursion potentially leading to denial of service or resource exhaustion on affected systems if an attacker can supply untrusted SGML catalogs locally. However, the maintainer indicates that triggering this issue is unlikely in practice since untrusted SGML catalogs are not realistically used. There are no known exploits in the wild, and the attack requires local access without privilege escalation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Given the maintainer's comments, the risk is mitigated by avoiding the use of untrusted SGML catalogs. No official fix or workaround has been published at this time.
CVE-2025-8732: Uncontrolled Recursion in libxml2
Description
A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recursion. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."
CVSS v4.0
Score 4.8medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in libxml2's xmlParseSGMLCatalog function leads to uncontrolled recursion when parsing untrusted SGML catalogs. It requires local attacker privileges and does not involve user interaction or elevated privileges. The maintainer doubts the real-world impact due to the obsolescence of SGML catalogs and the requirement to use untrusted catalogs to trigger the issue. The CVSS 4.8 score reflects limited attack vector and impact. No patch or vendor advisory has been provided.
Potential Impact
The vulnerability could cause uncontrolled recursion potentially leading to denial of service or resource exhaustion on affected systems if an attacker can supply untrusted SGML catalogs locally. However, the maintainer indicates that triggering this issue is unlikely in practice since untrusted SGML catalogs are not realistically used. There are no known exploits in the wild, and the attack requires local access without privilege escalation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Given the maintainer's comments, the risk is mitigated by avoiding the use of untrusted SGML catalogs. No official fix or workaround has been published at this time.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-08-08T07:49:27.806Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68962a34ad5a09ad00054f50
Added to database: 08/08/2025, 16:47:48 UTC
Last enriched: 06/02/2026, 20:06:26 UTC
Last updated: 09/10/2026, 19:24:58 UTC
Views: 218
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.