CVE-2025-59399
libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error message generation.
Scoring
- Severity
- LOW
- CVSS base score
- 3.1
- CVSS vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.17%
- CWE
- CWE-460
- Published
- 2025-09-15
- Last modified
- 2026-03-13
Affected products
- EVerest libocpp
Weakness type
Related vulnerabilities
- CVE-2026-86748 — Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
- CVE-2026-61387 — In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not...
- CVE-2026-48524 — PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2026-33481 — Syft improper temporary file cleanup
- CVE-2026-20118 — Cisco IOS-XR NCS 5500 and NCS 5700 Egress Packet Network Interfaces Aligner Interrupt Denial of Service Vulnerability
- CVE-2025-32439 — pleezer allows resource exhaustion through uncollected hook script processes
- CVE-2025-30157 — Envoy crashes when HTTP ext_proc processes local replies