PT-2025-26735 · Oatpp · Oatpp
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
oatpp Oat++ versions up to 1.3.1
Description:
A critical vulnerability has been found, affecting the
deserializeArray function in the file src/oatpp/json/Deserializer.cpp. This issue leads to a stack-based buffer overflow and can be initiated remotely.Recommendations:
For versions up to 1.3.1, consider disabling the
deserializeArray function as a temporary workaround until a patch is available. Restrict access to the src/oatpp/json/Deserializer.cpp file to minimize the risk of exploitation.Exploit
Fix
DoS
Buffer Overflow
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oatpp