HIGH 7.5 PyPI
copyparty allows Regex Denial of Service (ReDoS) in the upload listing
GHSA-5662-2rj7-f2v6 · CVE-2025-54796
Published · Modified
Description
Summary
The filter parameter for the "Recent uploads" page allows arbitrary Regexes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server.
PoC
https://127.0.0.1:3923/?ru&filter=(.+)+x
Impact
The server becomes fully inaccessible for a long time.
References
- WEB https://github.com/9001/copyparty/security/advisories/GHSA-5662-2rj7-f2v6
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-54796
- WEB https://github.com/9001/copyparty/commit/09910ba80784c3980947d92f45db696398c0fd83
- PACKAGE https://github.com/9001/copyparty
- WEB https://github.com/9001/copyparty/releases/tag/v1.18.9
Ready to move
Start Securing
Free, no credit card | First findings in minutes