CVE-2025-54796
HIGH7.5EPSS 0.32%copyparty allows Regex Denial of Service (ReDoS) in the upload listing
發布日:2025/8/4修改日:2025/8/4
描述
### Summary The `filter` parameter for the "Recent uploads" page allows arbitrary Regexes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. ### PoC `https://127.0.0.1:3923/?ru&filter=(.+)+x` ### Impact The server becomes fully inaccessible for a long time.
受影響套件(1)
- PyPI/copypartyfrom 0, < 1.18.9
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
參考連結(5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-54796
- PATCHhttps://github.com/9001/copyparty
- WEBhttps://github.com/9001/copyparty/commit/09910ba80784c3980947d92f45db696398c0fd83
- WEBhttps://github.com/9001/copyparty/releases/tag/v1.18.9
- WEBhttps://github.com/9001/copyparty/security/advisories/GHSA-5662-2rj7-f2v6