{"id":"PYSEC-2026-1969","summary":"TorBot vulnerable to Inefficient Regular Expression Complexity in validate_link","details":"### Summary\n_The torbot.modules.validators.validate_link function uses the python-validators URL validation regex. This particular regular expression has an exponential complexity which allows an attacker to cause an application crash using a well-crafted argument.._\n\n### Details\nhttps://github.com/DedSecInside/TorBot/blob/d2b89192379ad033ffc7044efff26e16ccc02d5a/torbot/modules/validators.py#L13\n\nAn attacker can use a well-crafted URL argument to exploit the vulnerability in the regular expression and cause a Denial of Service on the system.\n\n### PoC\nI have uploaded a secret gist containing a PoC (https://gist.github.com/ikkebr/6041055314f1cfb8e65b2a1acbaae12c). By adding one special character at the end of the user argument of the URL, the regular expression will take exponentially longer to compute.\n\nFor a string of size 10k, the regex will take 0.01s without the well-crafted URL and 1.3s with the well-crafted URL exploit.\nFor a string of size 50k, the regex will take 0.03s without the well-crafted URL and 35s with the well-crafted URL exploit.\nFor a string of size 100k, the regex will take 0.05s without the well-crafted URL and over 200s with the well-crafted URL exploit.\n\nThe regular expression used in the validators library versions [0.20, 0.11] is vulnerable to this attack. Version 0.21 appears to be unaffected, but it no longer contains a single regular expression.\n\n### Impact\nAn attacker could exploit this vulnerability to cause a denial of service or increased resource usage.\n","aliases":["CVE-2023-45813","GHSA-72qw-p7hh-m3ff"],"modified":"2026-07-07T17:48:05.329140268Z","published":"2026-07-07T11:45:25.857668Z","references":[{"type":"WEB","url":"https://github.com/DedSecInside/TorBot/security/advisories/GHSA-72qw-p7hh-m3ff"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45813"},{"type":"WEB","url":"https://github.com/DedSecInside/TorBot/commit/ef6e06bc7785355b1701d5524eb4550441086ac4"},{"type":"WEB","url":"https://gist.github.com/ikkebr/6041055314f1cfb8e65b2a1acbaae12c"},{"type":"PACKAGE","url":"https://github.com/DedSecInside/TorBot"},{"type":"WEB","url":"https://github.com/DedSecInside/TorBot/blob/d2b89192379ad033ffc7044efff26e16ccc02d5a/torbot/modules/validators.py#L13"},{"type":"PACKAGE","url":"https://pypi.org/project/torbot"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-72qw-p7hh-m3ff"}],"affected":[{"package":{"name":"torbot","ecosystem":"PyPI","purl":"pkg:pypi/torbot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.0"}]}],"versions":["1.2","2.1.0","3.0.1","3.1.1","3.1.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/torbot/PYSEC-2026-1969.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}