Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5662-2rj7-f2v6

Опубликовано: 04 авг. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

copyparty allows Regex Denial of Service (ReDoS) in the upload listing

Summary

The filter parameter for the "Recent uploads" page allows arbitrary Regexes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server.

PoC

https://127.0.0.1:3923/?ru&filter=(.+)+x

Impact

The server becomes fully inaccessible for a long time.

Пакеты

Наименование

copyparty

pip
Затронутые версииВерсия исправления

<= 1.18.8

1.18.9

EPSS

Процентиль: 19%
0.00061
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 7.5
nvd
6 месяцев назад

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. This is fixed in version 1.18.9.

EPSS

Процентиль: 19%
0.00061
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333