#VU114426 Reachable assertion in tinyxml2 - CVE-2024-50615
Published: August 26, 2025
tinyxml2
www.grinninglizard.com
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion in UINT_MAX/digit within the XMLUtil::GetCharacterRef() function in tinyxml2.cpp. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.