{"id":"CVE-2023-45813","aliases":["GHSA-72qw-p7hh-m3ff","PYSEC-2026-1969"],"title":"TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link","summary":"TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link","severity":"medium","cvss":4.6,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"torbot","product":"torbot","ecosystem":"pip","affected":["torbot < 4.0.0"],"patched":["torbot 4.0.0"],"published":"2023-10-19","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:58.632069820Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-72qw-p7hh-m3ff","references":[{"url":"https://github.com/DedSecInside/TorBot/security/advisories/GHSA-72qw-p7hh-m3ff"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45813"},{"url":"https://github.com/DedSecInside/TorBot/commit/ef6e06bc7785355b1701d5524eb4550441086ac4"},{"url":"https://gist.github.com/ikkebr/6041055314f1cfb8e65b2a1acbaae12c"},{"url":"https://github.com/DedSecInside/TorBot"},{"url":"https://github.com/DedSecInside/TorBot/blob/d2b89192379ad033ffc7044efff26e16ccc02d5a/torbot/modules/validators.py#L13"}],"tags":["osv","pip"],"epss":0.00804,"epssPercentile":0.55185,"ingestedAt":"2026-07-08T18:25:46.740Z","slug":"CVE-2023-45813","body":"## Overview\n\n### Summary\n_The torbot.modules.validators.validate_link function uses the python-validators URL validation regex. This particular regular expression has an exponential complexity which allows an attacker to cause an application crash using a well-crafted argument.._\n\n### Details\nhttps://github.com/DedSecInside/TorBot/blob/d2b89192379ad033ffc7044efff26e16ccc02d5a/torbot/modules/validators.py#L13\n\nAn attacker can use a well-crafted URL argument to exploit the vulnerability in the regular expression and cause a Denial of Service on the system.\n\n### PoC\nI have uploaded a secret gist containing a PoC (https://gist.github.com/ikkebr/6041055314f1cfb8e65b2a1acbaae12c). By adding one special character at the end of the user argument of the URL, the regular expression will take exponentially longer to compute.\n\nFor a string of size 10k, the regex will take 0.01s without the well-crafted URL and 1.3s with the well-crafted URL exploit.\nFor a string of size 50k, the regex will take 0.03s without the well-crafted URL and 35s with the well-crafted URL exploit.\nFor a string of size 100k, the regex will take 0.05s without the well-crafted URL and over 200s with the well-crafted URL exploit.\n\nThe regular expression used in the validators library versions [0.20, 0.11] is vulnerable to this attack. Version 0.21 appears to be unaffected, but it no longer contains a single regular expression.\n\n### Impact\nAn attacker could exploit this vulnerability to cause a denial of service or increased resource usage.\n\n\n## Affected packages\n\n- `torbot < 4.0.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `torbot 4.0.0`","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":25.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}