Vulnerability record · CVE-2025-40907 · published 16 May 2025
CVE-2025-40907: Fastcgi fcgi heap-based buffer overflow vulnerability
FFastcgi · Fcgi
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Description
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library. The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2025/04/23/4 | Mailing ListThird Party Advisory |
| https://github.com/FastCGI-Archives/fcgi2/issues/67 | ExploitIssue Tracking |
| https://github.com/FastCGI-Archives/fcgi2/releases/tag/2.4.5 | Release Notes |
| https://github.com/perl-catalyst/FCGI/issues/14 | ExploitIssue Tracking |
| https://patch-diff.githubusercontent.com/raw/FastCGI-Archives/fcgi2/pull/74.patch | Patch |
| https://www.synacktiv.com/en/publications/cve-2025-23016-exploiting-the-fastcgi-library | ExploitThird Party Advisory |
Track CVE-2025-40907 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-40907), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.