Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25266 | Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module |
Github GHSA |
GHSA-6fxp-p9mg-q64w | Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module |
Thu, 21 Aug 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module (issue 1 of 2). | Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings containing a large volume of whitespace without a terminating colon. An attacker who can control or inject docstring content into affected applications can trigger excessive CPU consumption. This software is used by Azure CLI. |
Thu, 21 Aug 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft knack |
|
| Vendors & Products |
Microsoft
Microsoft knack |
Thu, 21 Aug 2025 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 20 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module (issue 1 of 2). | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-21T15:37:24.848Z
Reserved: 2025-07-21T00:00:00.000Z
Link: CVE-2025-54363
Updated: 2025-08-20T13:37:46.727Z
Status : Deferred
Published: 2025-08-20T03:15:35.243
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-54363
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:59:06Z
EUVD
Github GHSA