DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CVE-2025-54363

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-54363

Severity

Unknown

Description

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings containing a large volume of whitespace without a terminating colon. An attacker who can control or inject docstring content into affected applications can trigger excessive CPU consumption. This software is used by Azure CLI.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-54363

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing