{"id":"CVE-2025-59398","details":"The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a CiString\u003c255\u003e object is created with StringTooLarge set to Throw.","modified":"2026-08-12T15:13:38.410158Z","published":"2025-09-15T00:00:00Z","database_specific":{"cna_assigner":"mitre","cwe_ids":["CWE-392"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59398.json"},"references":[{"type":"WEB","url":"https://github.com/EVerest/libocpp/compare/v0.26.1...v0.26.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59398.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59398"},{"type":"REPORT","url":"https://github.com/EVerest/everest-core/issues/1152"},{"type":"FIX","url":"https://github.com/EVerest/everest-core/commit/253432ae7458ad0445f68f9d716086090c2be49c"},{"type":"FIX","url":"https://github.com/EVerest/libocpp/commit/fb391b4ff16a0a07150e5a8eebf0856fb6623cbe"},{"type":"FIX","url":"https://github.com/EVerest/libocpp/pull/1052"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/everest/everest","events":[{"introduced":"0"},{"fixed":"253432ae7458ad0445f68f9d716086090c2be49c"}],"database_specific":{"source":"REFERENCES"}},{"type":"GIT","repo":"https://github.com/everest/libocpp","events":[{"introduced":"0"},{"fixed":"ec4949cc8d2887c9d19d97b44b9236b8b88a8a7b"},{"fixed":"fb391b4ff16a0a07150e5a8eebf0856fb6623cbe"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.26.2"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["2025.4.0-rc1","2025.3.0","2025.2.0","2025.1.0-rc2","2025.1.0-rc1","2024.11.0","2024.10.0","2024.9.0-rc1","2024.8.0","2024.7.1","2024.7.0","2024.6.0-rc2","2024.6.0-rc1","2024.5.0","2024.4.0","2024.3.0-rc1","2024.2.0","2024.1.0","2023.12.0","2023.10.0","2023.9.1","2023.9.0","2023.8.0","2023.7.0","2023.6.0","2023.5.0","2023.3.0","2023.2.1","2023.2.0","2023.1.0","2022.12.1","2022.12.0","v0.26.1","v0.26.0","v0.25.0","v0.24.2","v0.24.1","v0.23.0","v0.22.0","v0.21.0","v0.18.0","v0.20.0","v0.19.0","v0.17.2","v0.17.1","v0.17.0","v0.16.2","v0.16.1","v0.16.0","v0.15.1","v0.15.0","v0.14.0","v0.13.1","v0.13.0","v0.12.0","v0.11.0","v0.10.0","v0.9.8","v0.9.7","v0.9.6","v0.9.5","v0.9.4","v0.9.3","v0.8.7","v0.8.6","v0.8.5","v0.8.1","v0.8.0","v0.7.0","v0.6.1","v0.5.2","v0.5.1","v0.5.0","v0.4.1","v0.4.0","v0.3.0","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59398.json","vanir_signatures_modified":"2026-08-12T15:13:38Z","vanir_signatures":[{"source":"https://github.com/everest/libocpp/commit/fb391b4ff16a0a07150e5a8eebf0856fb6623cbe","target":{"file":"lib/ocpp/v2/charge_point.cpp"},"deprecated":false,"digest":{"line_hashes":["329914649163498463201405919058363773259","191782502361572714822329576504077630384","226063914280258387762726754857852685240","282922994923743629426707999042575520406","136402490273983162638423395517940998810","336988327875728139135200906983482269130","159050727889304491647948875706886107139","274997886602663972079959384348766130933"],"threshold":0.9},"id":"CVE-2025-59398-041f5ce1","signature_type":"Line","signature_version":"v1"},{"source":"https://github.com/everest/libocpp/commit/fb391b4ff16a0a07150e5a8eebf0856fb6623cbe","target":{"file":"lib/ocpp/v2/charge_point.cpp","function":"ChargePoint::message_callback"},"deprecated":false,"digest":{"function_hash":"85469999211743027846757861404581018417","length":7340},"id":"CVE-2025-59398-5b4b4810","signature_type":"Function","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/everest/libocpp/commit/fb391b4ff16a0a07150e5a8eebf0856fb6623cbe","target":{"file":"include/ocpp/common/message_queue.hpp"},"deprecated":false,"digest":{"line_hashes":["242458449135854739851948518810059249848","10575674806477531753861574198813457614","196977730058034066642156776201897383258","66770497864817877471414621064748994124","42650009989781155559769190597484297912","336142444310787340366234446267074719041","101177556271919559789197140705369459622"],"threshold":0.9},"id":"CVE-2025-59398-843a1bd5"},{"source":"https://github.com/everest/libocpp/commit/ec4949cc8d2887c9d19d97b44b9236b8b88a8a7b","target":{"file":"lib/ocpp/v16/charge_point_impl.cpp"},"deprecated":false,"digest":{"line_hashes":["144145004473872556552143305028902613851","35699249817163172743542849699616494166","53334171588760620306534512594036637971","135644134620645549806839062470264463781","240522512309630831697827857464120036961","308993836890266374978904906784019307354","162790871845912678158843320662248851176","208458563293752178943462957903839898449","276802959634391546605903458622506748095","78121856753964299456430525400299748860"],"threshold":0.9},"id":"CVE-2025-59398-9d9ffd92","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/everest/libocpp/commit/ec4949cc8d2887c9d19d97b44b9236b8b88a8a7b","target":{"file":"lib/ocpp/v16/charge_point_impl.cpp","function":"ChargePointImpl::handleResetRequest"},"deprecated":false,"digest":{"function_hash":"7070882406317729019080362432367989838","length":1358},"id":"CVE-2025-59398-f36ea4cc"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}