Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-54364

Опубликовано: 20 авг. 2025
Источник: debian
EPSS Низкий

Описание

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings containing a large volume of whitespace without a terminating colon. An attacker who can control or inject docstring content into affected applications can trigger excessive CPU consumption. This software is used by Azure CLI.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
knackunfixedpackage

Примечания

  • https://github.com/microsoft/knack/issues/281

  • Negligible security impact; disputed as security issue upstream in context

  • of its use by Azure CLI

EPSS

Процентиль: 28%
0.00357
Низкий

Связанные уязвимости

ubuntu
12 месяцев назад

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings containing a large volume of whitespace without a terminating colon. An attacker who can control or inject docstring content into affected applications can trigger excessive CPU consumption. This software is used by Azure CLI.

nvd
12 месяцев назад

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings containing a large volume of whitespace without a terminating colon. An attacker who can control or inject docstring content into affected applications can trigger excessive CPU consumption. This software is used by Azure CLI.

github
12 месяцев назад

Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module

EPSS

Процентиль: 28%
0.00357
Низкий