CVE 4.7 MEDIUM

EVerest affected by memory exhaustion in libocpp_CVE-2025-68138

4.7 / 10
MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Description

EVerest is an EV charging software stack, and EVerest libocpp is a C++ implementation of the Open Charge Point Protocol. In libocpp prior to version 0.30.1, pointers returned by the `strdup` calls are never freed. At each connection attempt, the newly allocated memory area will be leaked, potentially causing memory exhaustion and denial of service. Version 0.30.1 fixes the issue.

Basic Information

ID CVE-2025-68138
Source GitHub_M
Published Jan 21, 2026 at 19:30
Modified Jan 22, 2026 at 21:56

Affected Product

Vendor EVerest
Product everest-core
Version libocpp < 0.30.1
Affected Versions EVerest everest-core libocpp < 0.30.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.