Regular Expression Denial of Service in Microsoft Knack
CVE-2025-54364
6.9MEDIUM
What is CVE-2025-54364?
The Microsoft Knack 0.12.0 version contains a vulnerability within the knack.introspection module that exposes applications to Regular Expression Denial of Service (ReDoS) attacks. This can allow an attacker to send carefully crafted inputs that take an excessive amount of time to process, leading to service unavailability. Developers using this version should review their implementations of the Knack library to mitigate potential risks arising from these types of attacks. More information can be found in the official advisory.
Affected Version(s)
Knack 0.12.0