CVE-2025-54796 – Copyparty Denial of Service (DoS) Regular Expression Injection

The following table lists the changes that have been made to the
CVE-2025-54796 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 02, 2025

    Action Type Old Value New Value
    Added Description Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the “Recent Uploads” page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. This is fixed in version 1.18.9.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Added CWE CWE-400
    Added CWE CWE-833
    Added CWE CWE-1333
    Added Reference https://github.com/9001/copyparty/commit/09910ba80784c3980947d92f45db696398c0fd83
    Added Reference https://github.com/9001/copyparty/releases/tag/v1.18.9
    Added Reference https://github.com/9001/copyparty/security/advisories/GHSA-5662-2rj7-f2v6
Share the Post:

Related Posts