# CVE-2025-27113

## Summary

- **CVE ID:** CVE-2025-27113
- **Severity:** LOW
- **CVSS Score:** 2.9 (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
- **CWE:** CWE-476
- **Published:** Feb 18, 2025
- **Last Modified:** Sep 14, 2026

## Description

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.

## Affected Products

- xmlsoft — libxml2 (0)
- xmlsoft — libxml2 (2.13.0)

## References

- [CNA](https://gitlab.gnome.org/GNOME/libxml2/-/issues/861)
- [CVE](https://security.netapp.com/advisory/ntap-20250306-0004/)
- [CVE](http://seclists.org/fulldisclosure/2025/Apr/13)
- [CVE](http://seclists.org/fulldisclosure/2025/Apr/10)
- [CVE](http://seclists.org/fulldisclosure/2025/Apr/9)
- [CVE](http://seclists.org/fulldisclosure/2025/Apr/8)
- [CVE](http://seclists.org/fulldisclosure/2025/Apr/5)
- [CVE](http://seclists.org/fulldisclosure/2025/Apr/4)
- [CVE](http://seclists.org/fulldisclosure/2025/Apr/12)
- [CVE](http://seclists.org/fulldisclosure/2025/Apr/11)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/02/msg00028.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.05%
- **EPSS Percentile:** 62.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._