eProsima.Fast-DDS is vulnerable to Integer Overflow
50
Medium Risk
Affected versions of the package are vulnerable to CVE-2025-62599, CVE-2025-62600, CVE-2025-62601, CVE-2025-62602, CVE-2025-62603, and CVE-2025-64098 by fully refactoring the built-in deserializers in CDRMessage. The update introduces additional safety checks, including protections against arithmetic overflows during length validation, to ensure robust and secure deserialization. Also CVE-2025-62799, CVE-2025-64438 and CVE-2025-65016 were fixed.
You are affected if you are using a version that falls within the vulnerable range.
eProsima.Fast-DDS is vulnerable to Integer Overflow in versions 0.0.1 - 2.6.10 and 2.7.0 - 3.4.0.
Upgrade the eProsima.Fast-DDS library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant