{"id":"CVE-2025-6499","summary":"vstakhov libucl ucl_parser.c ucl_parse_multiline_string heap-based overflow","details":"A vulnerability classified as problematic was found in vstakhov libucl up to 0.9.2. Affected by this vulnerability is the function ucl_parse_multiline_string of the file src/ucl_parser.c. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.","modified":"2026-08-12T03:51:33.501986583Z","published":"2025-06-23T02:00:08.771Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6499.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6499.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6499"},{"type":"ADVISORY","url":"https://vuldb.com/?id.313615"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.601011"},{"type":"REPORT","url":"https://github.com/vstakhov/libucl/issues/319"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.313615"},{"type":"EVIDENCE","url":"https://github.com/user-attachments/files/19825399/libucl_crash.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vstakhov/libucl","events":[{"introduced":"edf094c0d2150e1494a877cbe06b651a306a0589"},{"last_affected":"f897d5a0fed3a4474a4c3137c7b92853845fed47"}],"database_specific":{"extracted_events":[{"introduced":"0.9.0"},{"last_affected":"0.9.0"},{"introduced":"0.9.1"},{"last_affected":"0.9.1"},{"introduced":"0.9.2"},{"last_affected":"0.9.2"},{"introduced":"0"}],"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:vstakhov:libucl:*:*:*:*:*:*:*:*"}}],"versions":["0.9.0","0.9.1","0.9.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6499.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}