CVE-2025-59728
Last modified
CVE-2025-59728 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. When calculating the content path in handling of MPEG-DASH manifests, there's an out-of-bounds NUL-byte write one byte past the end of the buffer.When we call xmlNodeGetContent below [0], it returns a buffer precisely allocated to match the string length, using strdup internally. If this buffer is not an empty string, it is assigned to root_url at [1].If the last (non-NUL) byte in this buffer is not '/' then we append '/' in-place at [2]. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
When calculating the content path in handling of MPEG-DASH manifests, there's an out-of-bounds NUL-byte write one byte past the end of the buffer.When we call xmlNodeGetContent below [0], it returns a buffer precisely allocated to match the string length, using strdup internally. If this buffer is not an empty string, it is assigned to root_url at [1].If the last (non-NUL) byte in this buffer is not '/' then we append '/' in-place at [2]. This will write two bytes into the buffer, starting at the last valid byte in the buffer, writing the NUL byte beyond the end of the allocated buffer. We recommend upgrading to version 8.0 or beyond.
Metrics
CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-59728?
How severe is CVE-2025-59728?
How do I fix CVE-2025-59728?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-59722Rejected reason: Not used
- CVE-2025-59723Rejected reason: Not used
- CVE-2025-59724Rejected reason: Not used
- CVE-2025-59725Rejected reason: Not used
- CVE-2025-59726Rejected reason: Not used
- CVE-2025-59727Rejected reason: Not used
- CVE-2025-59729When parsing the header for a DHAV file, there's an integer …5.7
- CVE-2025-5973A vulnerability classified as problematic was found in PHPGu…5.4
- CVE-2025-59730When decoding a frame for a SANM file (ANIM v0 variant), the…5.7
- CVE-2025-59731When decoding an OpenEXR file that uses DWAA or DWAB compres…6.9
- CVE-2025-59732When decoding an OpenEXR file that uses DWAA or DWAB compres…8.7
- CVE-2025-59733When decoding an OpenEXR file that uses DWAA or DWAB compres…8.7
Are you affected by CVE-2025-59728?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
