LOW3.7
PYSEC-2026-1270
configobj ReDoS exploitable by developer using values in a server-side configuration file
Quick fix
PYSEC-2026-1270 — configobj: upgrade to the fixed version with the command below.
pip install --upgrade 'configobj>=5.0.9'Details
All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). **Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-26112[ADVISORY]
- https://github.com/DiffSK/configobj/issues/232[WEB]
- https://github.com/DiffSK/configobj/commit/7c618b0bbaff6ecaca51a6f05b29795d1377a4a5[WEB]
- https://github.com/DiffSK/configobj[PACKAGE]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6BO4RLMYEJODCNUE3DJIIUUFVTPAG6VN[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZHY7B33EFY4LESP2NI4APQUPRROTAZK[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYU4IHVLOTYMFPH7KDOJGKZQR4GKWPFK[WEB]
- https://pypi.org/project/configobj/5.0.9[WEB]
- https://security.snyk.io/vuln/SNYK-PYTHON-CONFIGOBJ-3252494[WEB]
- https://pypi.org/project/configobj[PACKAGE]
- https://github.com/advisories/GHSA-c33w-24p9-8m24[ADVISORY]