Back to Database
Status published
Low
CVE-2025-59398
The OCPP implementation in libocpp before 0.26.2 allows a denial...
Vulnerability Description
The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a CiString<255> object is created with StringTooLarge set to Throw.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59398
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/EVerest/everest-core/issues/1152
- https://github.com/EVerest/everest-core/commit/253432ae7458ad0445f68f9d716086090c2be49c
- https://github.com/EVerest/libocpp/compare/v0.26.1...v0.26.2
- https://github.com/EVerest/libocpp/commit/fb391b4ff16a0a07150e5a8eebf0856fb6623cbe
- https://github.com/EVerest/libocpp/pull/1052
More from EVerest
View All →CVE-2025-68141
EVerest vulnerable to null pointer dereference during DC_ChargeLoopRes document deserialization
High
7.4
CVE-2025-68140
EVerest allows null session ID to bypass session ID verification
Medium
4.3
CVE-2025-68139
In EVerest, by default, the EV is responsible for closing the connection if the module encounters an error during request processing
Medium
4.3
CVE-2025-68138
EVerest affected by memory exhaustion in libocpp
Medium
4.7
CVE-2025-68137
EVerest's Integer Overflow and Signed to Unsigned conversion lead to either stack buffer overflow or infinite loop
High
8.4
Affected Vendor
EVerest
View all reports →Affected Software
libocpp
Vulnerable Versions:
0
Timeline
Official Publish:
September 15th, 2025
Last Modified:
September 15th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.