Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PoC-CVE-2025-25200 — ReDoS explorando backtracking em regex, resultando em consumo excessivo de CPU e negação de serviço (DoS) em aplicações Node.js. | Kitploit
Tools/GitHubGitHub/dwictor0/poc-cve-2025-25200
Static AnalysisVulnerability AnalysisExploitationWeb Security
GitHubdwictor0/poc-cve-2025-25200

PoC-CVE-2025-25200

ReDoS explorando backtracking em regex, resultando em consumo excessivo de CPU e negação de serviço (DoS) em aplicações Node.js.

View Repository
106 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-25200

Context

  • Vulnerability: CVE-2025-25200

  • Type: Regular Expression Denial of Service (ReDoS)

  • Component: Kao >= 2.0.0, < 2.15.4 , >= 3.0.0-alpha.0, < 3.0.0-alpha.3 , >= 1.0.0, < 1.7.1, < 0.21.2

  • Description: This vulnerability presents quadratic time complexity O(n²) or, in more critical scenarios, exponential O(2ⁿ), meaning the time required to process the input grows with its size (backtracking). The origin of the problem lies in the mechanism of the regular expression engine called backtracking. When the input (token) does not match, the engine simply retreats to previous positions where it could choose an alternative path.

NFA

Impact and Severity

  • Impact Type: Denial of Service (DoS)
  • Attack Vector: Network
  • Score: 9.2 (High)

Possible Mitigations

  • Payload length validation.
  • Use a WAF rule to sanitize or reject headers containing patterns that could trigger ReDoS.
  • Implement request timeout limits to prevent long-duration requests from blocking the event loop indefinitely.

Responsible Disclosure

This vulnerability was handled following responsible disclosure practices.

PoC Test Node.js Koa CVE-2025-25200

Download Tool