CVE-2025-54365

fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more. In version 3.0.1, the regular expression patched to mitigate the ReDoS vulnerability by limiting the length of string fails to catch inputs that exceed this limit. This type of patch fails to detect cases in which the string representing the attributes of a <script> tag exceeds 100 characters. As a result, most of the regex patterns present in version 3.0.1 can be bypassed. This is fixed in version 3.0.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fastapi-guard:fastapi_guard:3.0.1:*:*:*:*:*:*:*

History

09 Oct 2025, 15:46

Type Values Removed Values Added
CPE cpe:2.3:a:fastapi-guard:fastapi_guard:3.0.1:*:*:*:*:*:*:*
References () https://github.com/rennf93/fastapi-guard/commit/0829292c322d33dc14ab00c5451c5c138148035a - () https://github.com/rennf93/fastapi-guard/commit/0829292c322d33dc14ab00c5451c5c138148035a - Patch
References () https://github.com/rennf93/fastapi-guard/commit/d9d50e8130b7b434cdc1b001b8cfd03a06729f7f - () https://github.com/rennf93/fastapi-guard/commit/d9d50e8130b7b434cdc1b001b8cfd03a06729f7f - Patch
References () https://github.com/rennf93/fastapi-guard/security/advisories/GHSA-rrf6-pxg8-684g - () https://github.com/rennf93/fastapi-guard/security/advisories/GHSA-rrf6-pxg8-684g - Exploit, Vendor Advisory
CWE CWE-1333
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Fastapi-guard
Fastapi-guard fastapi Guard
Summary
  • (es) fastapi-guard es una librería de seguridad para FastAPI que proporciona middleware para controlar IP, registrar solicitudes, detectar intentos de penetración y más. En la versión 3.0.1, la expresión regular parcheada para mitigar la vulnerabilidad ReDoS limitando la longitud de la cadena no detecta las entradas que superan este límite. Este tipo de parche no detecta los casos en los que la cadena que representa los atributos de una etiqueta

24 Jul 2025, 14:15

Type Values Removed Values Added
References () https://github.com/rennf93/fastapi-guard/security/advisories/GHSA-rrf6-pxg8-684g - () https://github.com/rennf93/fastapi-guard/security/advisories/GHSA-rrf6-pxg8-684g -

23 Jul 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-23 23:15

Updated : 2025-10-09 15:46


NVD link : CVE-2025-54365

Mitre link : CVE-2025-54365

CVE.ORG link : CVE-2025-54365


JSON object : View

Products Affected

fastapi-guard

  • fastapi_guard
CWE
CWE-20

Improper Input Validation

CWE-185

Incorrect Regular Expression

CWE-1333

Inefficient Regular Expression Complexity