{"id":"CVE-2025-25285","aliases":["GHSA-x4c5-c7rf-jjgv"],"url":"https://o3.security/vulnerability/CVE-2025-25285","summary":"@octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking","details":"@octokit/endpoint turns REST API endpoints into generic request options. Starting in version 4.1.0 and prior to version 10.1.3, by crafting specific `options` parameters, the `endpoint.parse(options)` call can be triggered, leading to a regular expression denial-of-service (ReDoS) attack. This causes the program to hang and results in high CPU utilization. The issue occurs in the `parse` function within the `parse.ts` file of the npm package `@octokit/endpoint`. Version 10.1.3 contains a patch for the issue.","published":"2025-02-14T19:31:44.827Z","modified":"2026-07-15T01:48:53.349551276Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@octokit/endpoint","fixedVersion":"9.0.6"},{"ecosystem":"npm","name":"@octokit/endpoint","fixedVersion":"10.1.3"}],"fix":{"url":"https://github.com/octokit/endpoint.js/commit/6c9c5be033c450d436efb37de41b6470c22f7db8","label":"octokit/endpoint.js@6c9c5be"},"references":[{"type":"WEB","url":"https://github.com/octokit/endpoint.js/blob/main/src/parse.ts"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/25xxx/CVE-2025-25285.json"},{"type":"ADVISORY","url":"https://github.com/octokit/endpoint.js/security/advisories/GHSA-x4c5-c7rf-jjgv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-25285"},{"type":"FIX","url":"https://github.com/octokit/endpoint.js/commit/6c9c5be033c450d436efb37de41b6470c22f7db8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:53.349551276Z"}}