Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. This is fixed in version 1.18.9.
History

Mon, 04 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 04 Aug 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared 9001
9001 copyparty
Vendors & Products 9001
9001 copyparty

Sat, 02 Aug 2025 00:00:00 +0000

Type Values Removed Values Added
Description Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. This is fixed in version 1.18.9.
Title Copyparty is vulnerable to Regex Denial of Service (ReDoS) attacks through "Recent Uploads" page
Weaknesses CWE-1333
CWE-400
CWE-833
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-01T23:38:27.221Z

Updated: 2025-08-04T15:19:59.399Z

Reserved: 2025-07-29T16:50:28.395Z

Link: CVE-2025-54796

cve-icon Vulnrichment

Updated: 2025-08-04T15:19:50.022Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-02T00:15:26.550

Modified: 2025-08-04T16:15:34.217

Link: CVE-2025-54796

cve-icon Redhat

No data.