See how fastcgi compares to other vendors in security performance
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.
The included FastCGI library is affected by <a href="https://access.redhat.com/security/cve/CVE-2025-23016">CVE-2025-23016</a>, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.
Version 2.4.5 of the fastcgi library was released last week: https://github.com/FastCGI-Archives/fcgi2/releases/tag/2.4.5
It fixed CVE-2025-23016, which is described as "an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c."
The upstream bug report can be found at: https://github.com/FastCGI-Archives/fcgi2/issues/67
and a detailed writeup from the discoverers at: https://www.synacktiv.com/en/publications/cve-2025-23016-exploiting-the-fastcgi-library
which suggests both upgrading to the fixed version and "limiting potential remote access to the FastCGI socket by declaring it as a UNIX socket."
-- -Alan Coopersmith- alan.coopersmith () oracle com Oracle Solaris Engineering - https://blogs.oracle.com/solaris