NULL pointer dereference in PUPnP - #VU134843
Published: June 18, 2026
PUPnP
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to null pointer dereference in ixmlNode_compare when comparing DOM nodes with NULL fields. A remote attacker can trigger comparison of crafted attribute objects to cause a denial of service.
The issue is reachable through removeAttributeNode during processing of attacker-controlled XML.