CVE 7.8 HIGH

fastapi-guard patch contains bypassable RegEx_CVE-2025-54365

7.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:P

Description

fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more. In version 3.0.1, the regular expression patched to mitigate the ReDoS vulnerability by limiting the length of string fails to catch inputs that exceed this limit. This type of patch fails to detect cases in which the string representing the attributes of a <script> tag exceeds 100 characters. As a result, most of the regex patterns present in version 3.0.1 can be bypassed. This is fixed in version 3.0.2.

Basic Information

ID CVE-2025-54365
Source GitHub_M
Published Jul 23, 2025 at 22:11
Modified Jul 24, 2025 at 13:36

Affected Product

Vendor rennf93
Product fastapi-guard
Version >= 3.0.1, < 3.0.2
Affected Versions rennf93 fastapi-guard >= 3.0.1, < 3.0.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.