LOW 3.7 PyPI

configobj ReDoS exploitable by developer using values in a server-side configuration file

GHSA-c33w-24p9-8m24 · CVE-2023-26112 · PYSEC-2026-1270

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)((.*)). Note: This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.

Ready to move

Start Securing

Free, no credit card | First findings in minutes