{"id":"PYSEC-2026-1270","summary":"configobj ReDoS exploitable by developer using values in a server-side configuration file","details":"All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\\((.*)\\). **Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.","aliases":["CVE-2023-26112","GHSA-c33w-24p9-8m24"],"modified":"2026-07-07T17:47:12.898028785Z","published":"2026-07-07T11:45:17.786428Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26112"},{"type":"WEB","url":"https://github.com/DiffSK/configobj/issues/232"},{"type":"WEB","url":"https://github.com/DiffSK/configobj/commit/7c618b0bbaff6ecaca51a6f05b29795d1377a4a5"},{"type":"PACKAGE","url":"https://github.com/DiffSK/configobj"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6BO4RLMYEJODCNUE3DJIIUUFVTPAG6VN"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZHY7B33EFY4LESP2NI4APQUPRROTAZK"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYU4IHVLOTYMFPH7KDOJGKZQR4GKWPFK"},{"type":"WEB","url":"https://pypi.org/project/configobj/5.0.9"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-PYTHON-CONFIGOBJ-3252494"},{"type":"PACKAGE","url":"https://pypi.org/project/configobj"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-c33w-24p9-8m24"}],"affected":[{"package":{"name":"configobj","ecosystem":"PyPI","purl":"pkg:pypi/configobj"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.9"}]}],"versions":["4.4.0","4.5.0","4.5.1","4.5.2","4.5.3","4.6.0","4.7.0","4.7.1","4.7.2","5.0.0","5.0.1","5.0.2","5.0.3","5.0.4","5.0.5","5.0.6","5.0.7","5.0.8"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/configobj/PYSEC-2026-1270.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}