Docopt is a command-line argument parser library with a narrow product footprint centered on its C++ implementation, which sees use in applications requiring structured option and argument handling. The observed vulnerability signal centers on integer overflow and wraparound conditions in parsing logic, reflecting the complexity of bounds validation in argument processing. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Docopt over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67125MEDIUM A signed integer overflow in docopt.cpp v0.6.2 (LeafPattern::match in docopt_private.h) when merging occurrence counters (e.g., default LONG_MAX + first user "-v/--verbose") can ca | Jan 23, 2026 | 4.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Docopt.
Media articles that mention a CVE ID that affects a product developed by Docopt — matched by CVE ID, not by vendor name.