CVE-2025-62689

NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:libmicrohttpd:*:*:*:*:*:*:*:*

History

14 Nov 2025, 18:05

Type Values Removed Values Added
References () https://git.gnunet.org/libmicrohttpd.git/commit/?id=ff13abc1c1d7d2b30d69d5c0bd4a237e1801c50b - () https://git.gnunet.org/libmicrohttpd.git/commit/?id=ff13abc1c1d7d2b30d69d5c0bd4a237e1801c50b - Patch
References () https://jvn.jp/en/jp/JVN76719218/ - () https://jvn.jp/en/jp/JVN76719218/ - Third Party Advisory
References () https://www.gnu.org/software/libmicrohttpd/ - () https://www.gnu.org/software/libmicrohttpd/ - Product
First Time Gnu
Gnu libmicrohttpd
CPE cpe:2.3:a:gnu:libmicrohttpd:*:*:*:*:*:*:*:*

10 Nov 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-10 05:15

Updated : 2025-11-14 18:05


NVD link : CVE-2025-62689

Mitre link : CVE-2025-62689

CVE.ORG link : CVE-2025-62689


JSON object : View

Products Affected

gnu

  • libmicrohttpd
CWE
CWE-122

Heap-based Buffer Overflow