HIGH7.5
PYSEC-2026-1275
copyparty allows Regex Denial of Service (ReDoS) in the upload listing
Quick fix
PYSEC-2026-1275 — copyparty: upgrade to the fixed version with the command below.
pip install --upgrade 'copyparty>=1.18.9'Details
### Summary The `filter` parameter for the "Recent uploads" page allows arbitrary Regexes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server.
### PoC `https://127.0.0.1:3923/?ru&filter=(.+)+x`
### Impact The server becomes fully inaccessible for a long time.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/9001/copyparty/security/advisories/GHSA-5662-2rj7-f2v6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-54796[ADVISORY]
- https://github.com/9001/copyparty/commit/09910ba80784c3980947d92f45db696398c0fd83[WEB]
- https://github.com/9001/copyparty[PACKAGE]
- https://github.com/9001/copyparty/releases/tag/v1.18.9[WEB]
- https://pypi.org/project/copyparty[PACKAGE]
- https://github.com/advisories/GHSA-5662-2rj7-f2v6[ADVISORY]