Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. This is fixed in version 1.18.9.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 04 Aug 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
9001
9001 copyparty |
|
Vendors & Products |
9001
9001 copyparty |
Sat, 02 Aug 2025 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. This is fixed in version 1.18.9. | |
Title | Copyparty is vulnerable to Regex Denial of Service (ReDoS) attacks through "Recent Uploads" page | |
Weaknesses | CWE-1333 CWE-400 CWE-833 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-01T23:38:27.221Z
Updated: 2025-08-04T15:19:59.399Z
Reserved: 2025-07-29T16:50:28.395Z
Link: CVE-2025-54796

Updated: 2025-08-04T15:19:50.022Z

Status : Awaiting Analysis
Published: 2025-08-02T00:15:26.550
Modified: 2025-08-04T16:15:34.217
Link: CVE-2025-54796

No data.