CVE-2025-54363 - CVE House
Back to Database
Status published Medium CVE-2025-54363

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS)...

Vulnerability Description

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings containing a large volume of whitespace without a terminating colon. An attacker who can control or inject docstring content into affected applications can trigger excessive CPU consumption. This software is used by Azure CLI.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54363

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Knack
Vulnerable Versions:
0.12.0

Timeline

Official Publish: August 20th, 2025
Last Modified: August 21st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)