PT-2025-30607 · Unknown · Fastapi Guard
Dhki
·
Published
2025-07-23
·
Updated
2025-07-24
·
CVE-2025-54365
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
fastapi-guard versions 3.0.1
Description
The regular expression patch intended to mitigate a ReDoS vulnerability failed to adequately limit input string length. Specifically, the patch did not account for cases where the attributes within a
<script> tag exceeded 100 characters, allowing bypass of the regex patterns. This could potentially lead to attacks such as Cross-Site Scripting (XSS) and SQL Injection.Recommendations
fastapi-guard version 3.0.1: Upgrade to version 3.0.2 to address the issue.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fastapi Guard