CVE-2025-40907: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.
The included FastCGI library is affected by <a href="https://access.redhat.com/security/cve/CVE-2025-23016">CVE-2025-23016</a>, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Other sources
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.
The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40907?
CVE-2025-40907 has a high severity due to the potential for heap-based buffer overflow that can be exploited by attackers.
How do I fix CVE-2025-40907?
To fix CVE-2025-40907, upgrade the FastCGI library to a version that is higher than 0.82.
What versions are affected by CVE-2025-40907?
CVE-2025-40907 affects FastCGI versions from 0.44 through 0.82.
What vulnerabilities are associated with CVE-2025-40907?
CVE-2025-40907 is associated with CVE-2025-23016, which involves an integer overflow leading to a buffer overflow.
What products utilize the affected FastCGI versions in CVE-2025-40907?
The vulnerability in CVE-2025-40907 primarily affects the FastCGI product line, specifically versions 0.44 through 0.82.