Products
Government
Resources
Community
Company
Partners
Sign In / Join
Sign In
Advisories
Microsoft Knack (knack.introspection module) Python Package ReDoS
Go Back
severity
medium
date
August 1, 2025
Affecting
knack 0.12.0
CVE
CVE-2025-54363
CVE-2025-54364
CVE type
Regular Expression Denial of Service (ReDoS)
CVSS
6.9
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
References
GitHub Repo
CVE-2025-54363 CVE Record
CVE-2025-54364 CVE Record
Credit
Sajeeb Lohani of Bugcrowd Security Innovation Lab