CVE-2025-54365 - CVE House
Back to Database
Status published High CVE-2025-54365

fastapi-guard patch contains bypassable RegEx

Vulnerability Description

fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more. In version 3.0.1, the regular expression patched to mitigate the ReDoS vulnerability by limiting the length of string fails to catch inputs that exceed this limit. This type of patch fails to detect cases in which the string representing the attributes of a <script> tag exceeds 100 characters. As a result, most of the regex patterns present in version 3.0.1 can be bypassed. This is fixed in version 3.0.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54365

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

fastapi-guard
Vulnerable Versions:
>= 3.0.1, < 3.0.2

Timeline

Official Publish: July 23rd, 2025
Last Modified: July 24th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)