knack
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting knackpage 1 of 1
- CVE-2025-54363NONECVSS 0.0EG 0.02025-08-20
vulnerable: 0.0.1 ... 0.9.0 (39 versions)
Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is suscep…
- CVE-2025-54364NONECVSS 0.0EG 0.02025-08-20
vulnerable: 0.0.1 ... 0.9.0 (39 versions)
Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastr…
Check whether knack is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for knack CVEs against the assets you own.
Start Free Scan →