GHSA-xfhg-9pjg-xg7g · Severity: high · Ecosystem: pip — VTK NULL pointer dereference vulnerability
There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that NULL pointer dereference may crash the application.
Conclusion & alert: CVE-2021-42521 is rated High Exploit Risk (66.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.07%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-25 | 1.03% | 1.07% | +0.04% |
| 2 | 2026-06-15 | 0.48% | 1.03% | +0.54% |
| 3 | 2026-05-12 | — | 0.48% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-xfhg-9pjg-xg7g · Severity: high · Ecosystem: pip — VTK NULL pointer dereference vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2021-42521 not yet assigned priority: Debian including 3 source packages (vtk6, vtk7, vtk9), 7 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 4, resolved 3. | https://security-tracker.debian.org/tracker/CVE-2021-42521 |
ubuntu
|
medium | CVE-2021-42521 medium priority: Ubuntu including 4 source packages (vtk, vtk6, vtk7, vtk9), 52 status rows across 13 suites (bionic, focal, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 30, needed 14, ignored 6, not-affected 1, released 1. | https://ubuntu.com/security/CVE-2021-42521 |