Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25267 | Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module |
Github GHSA |
GHSA-xh9h-692f-mmg4 | Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module |
Tue, 26 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Thu, 21 Aug 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module (issue 2 of 2). | Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings containing a large volume of whitespace without a terminating colon. An attacker who can control or inject docstring content into affected applications can trigger excessive CPU consumption. This software is used by Azure CLI. |
Thu, 21 Aug 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft knack |
|
| Vendors & Products |
Microsoft
Microsoft knack |
Wed, 20 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module (issue 2 of 2). | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-26T13:42:50.158Z
Reserved: 2025-07-21T00:00:00.000Z
Link: CVE-2025-54364
Updated: 2025-08-20T13:33:47.413Z
Status : Deferred
Published: 2025-08-20T03:15:35.443
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-54364
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:59:06Z
EUVD
Github GHSA