VYPR
Low severity3.7NVD Advisory· Published Apr 3, 2023· Updated Jun 17, 2026

CVE-2023-26112

CVE-2023-26112

Description

All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). Note: This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
configobjPyPI
< 5.0.95.0.9

Affected products

27

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.