CVE-2025-6566: Oatpp Oat++

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability was found in oatpp Oat++ up to 1.3.1. It has been declared as critical. This vulnerability affects the function deserializeArray of the file src/oatpp/json/Deserializer.cpp. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Affected products

  • Oatpp Oat++: up to and including 1.3.1

Published 2025-06-24. Last modified 2026-06-17.