PT-2025-26735 · Oatpp · Oatpp

·

CVE-2025-6566

·

Published

2025-06-24

·

Updated

2025-08-18

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: oatpp Oat++ versions up to 1.3.1
Description: A critical vulnerability has been found, affecting the deserializeArray function in the file src/oatpp/json/Deserializer.cpp. This issue leads to a stack-based buffer overflow and can be initiated remotely.
Recommendations: For versions up to 1.3.1, consider disabling the deserializeArray function as a temporary workaround until a patch is available. Restrict access to the src/oatpp/json/Deserializer.cpp file to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-6566

Affected Products

Oatpp