{"id":"CVE-2025-3588","summary":"joelittlejohn jsonschema2pojo JSON File SchemaRule.java apply stack-based overflow","details":"A vulnerability, which was classified as problematic, has been found in joelittlejohn jsonschema2pojo 1.2.2. This issue affects the function apply of the file org/jsonschema2pojo/rules/SchemaRule.java of the component JSON File Handler. The manipulation leads to stack-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","aliases":["GHSA-66rc-vg9f-48m7"],"modified":"2026-07-15T01:49:08.730800453Z","published":"2025-04-14T20:31:04.933Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3588.json","cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-121"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3588.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3588"},{"type":"ADVISORY","url":"https://vuldb.com/?id.304643"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.550136"},{"type":"REPORT","url":"https://github.com/joelittlejohn/jsonschema2pojo/issues/1672"},{"type":"REPORT","url":"https://github.com/joelittlejohn/jsonschema2pojo/issues/1672#issue-2968446816"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.304643"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/joelittlejohn/jsonschema2pojo","events":[{"introduced":"115641cae67c0d450b1584d5770bcbb2a795ba5b"},{"last_affected":"115641cae67c0d450b1584d5770bcbb2a795ba5b"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.2.2"},{"last_affected":"1.2.2"}]}}],"versions":["1.2.2","jsonschema2pojo-1.2.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3588.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}