CVE-2023-26112Low· 3.7▾ Sunlitconfigobj ReDoS exploitable by developer using values in a server-side configuration file
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
1.3%
1.3% → 1.3%
Last analysed / modified upstream
All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)((.*)). Note: This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.
configobj < 5.0.9Upgrade to a patched release:
configobj 5.0.9