PT-2025-30607 · Unknown · Fastapi Guard

Dhki

·

Published

2025-07-23

·

Updated

2025-07-24

·

CVE-2025-54365

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions fastapi-guard versions 3.0.1
Description The regular expression patch intended to mitigate a ReDoS vulnerability failed to adequately limit input string length. Specifically, the patch did not account for cases where the attributes within a <script> tag exceeded 100 characters, allowing bypass of the regex patterns. This could potentially lead to attacks such as Cross-Site Scripting (XSS) and SQL Injection.
Recommendations fastapi-guard version 3.0.1: Upgrade to version 3.0.2 to address the issue.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-54365
GHSA-RRF6-PXG8-684G

Affected Products

Fastapi Guard