CVE-2025-53539 - CVE House
Back to Database
Status published Medium CVE-2025-53539

ReDoS in fastapi-guard's penetration attempts detector

Vulnerability Description

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. fastapi-guard's penetration attempts detection uses regex to scan incoming requests. However, some of the regex patterns used in detection are extremely inefficient and can cause polynomial complexity backtracks when handling specially crafted inputs. This vulnerability is fixed in 3.0.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53539

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

fastapi-guard
Vulnerable Versions:
< 3.0.1

Timeline

Official Publish: July 7th, 2025
Last Modified: July 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)