← back
CVE-2025-40907mediumCWE-122CWE-1395CWE-190

FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 0.6%
exploitation probability
0.6%top 56% of all CVEs
observed exploitation
nono source reports it
In short

The Perl FCGI module versions 0.44 to 0.82 include a vulnerable FastCGI library that can be exploited by sending crafted data to cause a crash or potentially execute code on the server.

Technical detail

An integer overflow in the FastCGI fcgi2 library's ReadParams function (fcgiapp.c) allows remote attackers to trigger a heap-based buffer overflow via malicious nameLen or valueLen values in IPC socket data. Exploitation requires the ability to send crafted FastCGI protocol messages to the application.

Summary generated and translated by AI from the official description.
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
ETHER · FCGI