ObjectWrapper Null Pointer Dereference in oatpp by Oat++ Framework
CVE-2026-1990
Key Information:
- Vendor
Oat++ Framework
- Status
- Vendor
- CVE Published:
- 6 February 2026
Badges
What is CVE-2026-1990?
A vulnerability has been identified in the Oat++ framework, specifically within the function oatpp::data::type::ObjectWrapper::ObjectWrapper located in src/oatpp/data/type/Type.hpp. This issue can lead to a null pointer dereference when accessed locally, making it essential for developers to be aware of the potential for exploitation. The vulnerability has been publicized, highlighting the community's concern as the project maintainers have yet to address the problem despite being informed through an issue report.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
oatpp 1.3.0
oatpp 1.3.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
