CVE-2023-26112
CVE-2023-26112
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.7EPSS 1.3%KEV nãoPoC —Patch —
Lifecycle
03 Apr 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\).
**Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P
Affected products
n/a · configobjWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://github.com/DiffSK/configobj/issues/232https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6BO4RLMYEJODCNUE3DJIIUUFVTPAG6VN/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZHY7B33EFY4LESP2NI4APQUPRROTAZK/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYU4IHVLOTYMFPH7KDOJGKZQR4GKWPFK/https://security.snyk.io/vuln/SNYK-PYTHON-CONFIGOBJ-3252494