# CVE-2025-54796

## Summary

- **CVE ID:** CVE-2025-54796
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-400, CWE-1333, CWE-833
- **Published:** Aug 1, 2025
- **Last Modified:** Mar 12, 2026

## Description

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. This is fixed in version 1.18.9.

## Affected Products

- 9001 — copyparty (< 1.18.9)

## References

- [CNA](https://github.com/9001/copyparty/security/advisories/GHSA-5662-2rj7-f2v6)
- [CNA](https://github.com/9001/copyparty/commit/09910ba80784c3980947d92f45db696398c0fd83)
- [CNA](https://github.com/9001/copyparty/releases/tag/v1.18.9)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.40%
- **EPSS Percentile:** 33.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._