CVE-2025-67125 is a signed integer overflow vulnerability in docopt.cpp v0.6.2, specifically within the LeafPattern::match function, affecting applications that utilize this library. This flaw occurs when merging occurrence counters, potentially leading to counter wrap and subsequent logic or policy bypasses in applications relying on these counters for limits, rate-gating, or safety mechanisms. Rated as MEDIUM severity (CVSS 4.4), the vulnerability requires user interaction (UI:R) and local access (AV:L) to exploit, resulting in low impact to integrity and availability (I:L/A:L). In hardened builds, it can also cause a Denial of Service (DoS) through process abort. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.6.2CPE matchmatch criteria | cpe:2.3:a:docopt:docopt.cpp:0.6.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.