
Cloud Vulnerability DB
A community-led vulnerabilities database
Microsoft Knack 0.12.0 contains a Regular Expression Denial of Service (ReDoS) vulnerability in the knack.introspection module, identified as CVE-2025-54364. The vulnerability was discovered in August 2025 and affects the option_descriptions function. This package is notably used by Azure CLI, making it a significant component in Microsoft's cloud infrastructure tooling (VulnCheck Advisory, NVD).
The vulnerability stems from an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" in the option_descriptions function. This pattern is susceptible to catastrophic backtracking when processing crafted docstrings containing a large volume of whitespace without a terminating colon. The vulnerability has been assigned a CVSS v4.0 Base Score of 6.9 (Medium) with the vector string CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N (NVD, VulnCheck Advisory).
When exploited, this vulnerability can trigger excessive CPU consumption and degrade system performance over time. The processing time increases exponentially with input size, potentially leading to resource exhaustion and denial of service conditions. This is particularly concerning for applications using Azure CLI, as it could affect cloud infrastructure management capabilities (VulnCheck Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."