CVE-2025-59777
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.43%
- CWE
- CWE-476
- Published
- 2025-11-10
- Last modified
- 2026-03-13
Affected products
- GNU Project GNU libbmicrohttpd
- GNU Project GNU libbmicrohttpd
Weakness type
Related vulnerabilities
- CVE-2026-78130 — strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute...
- CVE-2026-78126 — strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
- CVE-2026-45747 — Suricata lua/tls: null dereference in TlsGetCertInfo
- CVE-2026-86547 — mrubyc through 4.0.0 NULL Pointer Dereference via OP_ENTER
- CVE-2026-66303 — Skype for Business and Lync Denial of Service Vulnerability
- CVE-2026-77901 — Microsoft Office Word Remote Code Execution Vulnerability
- CVE-2026-70575 — Windows Schannel Denial of Service Vulnerability
- CVE-2026-69881 — Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability