CVE-2025-40907
published 2025-05-16CVE-2025-40907: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.56%
43.6th percentile
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.
The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libfcgi-perl | < libfcgi-perl 0.79+ds-2 (bookworm) | libfcgi-perl 0.79+ds-2 (bookworm) |
| fastcgi | fcgi | 0.44 – 0.82 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libfcgi-perl vulnerability
vendor_ubuntu·2025-05-22
CVE-2025-40907 libfcgi-perl vulnerability
Title: libfcgi-perl vulnerability
Summary: libfcgi-perl could be made to crash or execute arbitrary code.
It was discovered that libfcgi-perl incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl-fcgi: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library
vendor_redhat·2025-05-16·CVSS 9.3
CVE-2025-40907 [CRITICAL] CWE-1395 perl-fcgi: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library
perl-fcgi: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.
The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
A flaw was found in the FCGI library. In affected versions, specially crafted nameLen or valueLen values in data sent to the IPC socket may result in a heap-based buffer overflow, which can cause an application crash or other undefined behavior. This occurs in ReadParams in fcgiapp.c.
Statement: This vulnerability is Impor
Debian
CVE-2025-40907: libfcgi-perl - FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the F...
vendor_debian·2025·CVSS 9.3
CVE-2025-40907 [CRITICAL] CVE-2025-40907: libfcgi-perl - FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the F...
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Scope: local
bookworm: resolved (fixed in 0.79+ds-2)
bullseye: resolved (fixed in 0.79+ds-2)
forky: resolved (fixed in 0.79+ds-2)
sid: resolved (fixed in 0.79+ds-2)
trixie: resolved (fixed in 0.79+ds-2)
OSV
CVE-2025-40907: FCGI versions 0
osv·2025-05-16·CVSS 9.3
CVE-2025-40907 [CRITICAL] CVE-2025-40907: FCGI versions 0
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
GHSA
GHSA-488m-4fx8-f36v: FCGI versions 0
ghsa_unreviewed·2025-05-16·CVSS 9.3
CVE-2025-40907 [CRITICAL] CWE-122 GHSA-488m-4fx8-f36v: FCGI versions 0
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.
The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2025/04/23/4https://github.com/FastCGI-Archives/fcgi2/issues/67https://github.com/FastCGI-Archives/fcgi2/releases/tag/2.4.5https://github.com/perl-catalyst/FCGI/issues/14https://patch-diff.githubusercontent.com/raw/FastCGI-Archives/fcgi2/pull/74.patchhttps://www.synacktiv.com/en/publications/cve-2025-23016-exploiting-the-fastcgi-library
2025-05-16
Published