CVE-2025-8732 | libxml2 up to 2.14.5 xmlcatalog xmlParseSGMLCatalog recursion (Issue 958 / EUVD-2025-24001)
A vulnerability classified as problematic has been found in libxml2 up to 2.14.5. The impacted element is the function xmlParseSGMLCatalog of the component xmlcatalog. Performing manipulation results in uncontrolled recursion.
This vulnerability is reported as CVE-2025-8732. The attack requires a local approach. Moreover, an exploit is present.
The real existence of this vulnerability is still doubted at the moment.
The code maintainer explains, that "[t]he issue can only be triggered with untrusted SGML catalogs and it makes absolutely no sense to use untrusted catalogs. I also doubt that anyone is still using SGML catalogs at all."