CVE-2025-6566

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-6566
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-6566.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-6566
Published
2025-06-24T13:15:25.057Z
Modified
2025-11-17T04:09:37.535186Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was found in oatpp Oat++ up to 1.3.1. It has been declared as critical. This vulnerability affects the function deserializeArray of the file src/oatpp/json/Deserializer.cpp. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

References

Affected packages

Git / github.com/oatpp/oatpp

Affected ranges

Type
GIT
Repo
https://github.com/oatpp/oatpp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

0.*

0.19.1
0.19.1-2
0.19.10
0.19.11
0.19.12
0.19.4
0.19.6
0.19.7
0.19.8
0.19.9

1.*

1.0.0
1.1.0
1.2.0
1.2.5
1.3.0
1.3.0-latest
1.3.1

v0.*

v0.18.12-alpha
v0.18.9-alpha