PT-2025-38131 · Xen+2 · Xapi+1

·

CVE-2025-58146

·

Published

2025-09-17

·

Updated

2026-07-09

CVSS v4.0

9.4

Critical

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions XAPI (affected versions not specified)
Description Multiple issues in XAPI can lead to a Denial of Service. First, while updates to the database sanitize input strings, the notification generation process uses unsanitized input, which can cause the database event thread to terminate and stop processing. Second, a discrepancy between the UTF-8 encoder (Unicode spec v3.0) and other internal libraries (Unicode spec v3.1) allows certain strings to be accepted and stored in the database, which subsequently prevents the database from being loaded. Third, there is a lack of input sanitization for Map/Set updates on objects within the database.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-58146
MGASA-2025-0270

Affected Products

Xapi
Xen