CVE-2025-59398: Everest Libocpp

Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.

The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a CiString<255> object is created with StringTooLarge set to Throw.

Affected products

  • Everest Libocpp: before 0.26.2 (fixed in 0.26.2)

Published 2025-09-15. Last modified 2026-06-17.