Loading HuntDB...

GHSA-9825-56cx-cfg6

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

Related CVEs

Key Information

GHSA ID
GHSA-9825-56cx-cfg6
Published
January 10, 2025 12:30 PM
Last Modified
April 24, 2025 12:31 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 9, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.