Fastcgi is a niche web-application interface standard implemented across various web servers and application frameworks, with its vulnerability footprint centered on the fcgi protocol implementation itself. The observed weakness classes—heap-based buffer overflows, improper input validation, and integer overflow conditions—reflect the low-level parsing and memory-handling requirements inherent to a protocol that bridges web servers and backend applications. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fastcgi over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-23016CRITICAL FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This | Jan 10, 2025 | 9.3 | 30 | NO | NO |
CVE-2012-6687MEDIUM FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections. | Feb 19, 2015 | 5.0 | 21 | NO | NO |
CVE-2025-40907MEDIUM FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.
The included FastCGI library is affected by CVE-2025-23016, causi | May 16, 2025 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fastcgi.
Media articles that mention a CVE ID that affects a product developed by Fastcgi — matched by CVE ID, not by vendor name.