CVE-2025-54796

HIGH7.5EPSS 0.32%

copyparty allows Regex Denial of Service (ReDoS) in the upload listing

Published: 8/4/2025Modified: 8/4/2025
Also known as:GHSA-5662-2rj7-f2v6

Description

### Summary The `filter` parameter for the "Recent uploads" page allows arbitrary Regexes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. ### PoC `https://127.0.0.1:3923/?ru&filter=(.+)+x` ### Impact The server becomes fully inaccessible for a long time.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (5)