{"api_version":"1","generated_at":"2026-07-24T21:28:47+00:00","cve":"CVE-2023-26112","urls":{"html":"https://cve.report/CVE-2023-26112","api":"https://cve.report/api/cve/CVE-2023-26112.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-26112","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-26112"},"summary":{"title":"CVE-2023-26112","description":"All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\\((.*)\\).\r\r**Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.","state":"PUBLIC","assigner":"report@snyk.io","published_at":"2023-04-03 05:15:00","updated_at":"2023-11-07 04:09:00"},"problem_types":["CWE-1333"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZHY7B33EFY4LESP2NI4APQUPRROTAZK/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZHY7B33EFY4LESP2NI4APQUPRROTAZK/","refsource":"MISC","tags":[],"title":"[SECURITY] Fedora 37 Update: python-configobj-5.0.8-6.fc37 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"429"},{"url":"https://github.com/DiffSK/configobj/issues/232","name":"https://github.com/DiffSK/configobj/issues/232","refsource":"MISC","tags":[],"title":"A ReDoS vulnerability exists in ./src/configobj/validate.py  · Issue #232 · DiffSK/configobj · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYU4IHVLOTYMFPH7KDOJGKZQR4GKWPFK/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYU4IHVLOTYMFPH7KDOJGKZQR4GKWPFK/","refsource":"MISC","tags":[],"title":"[SECURITY] Fedora 39 Update: python-configobj-5.0.8-6.fc39 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6BO4RLMYEJODCNUE3DJIIUUFVTPAG6VN/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6BO4RLMYEJODCNUE3DJIIUUFVTPAG6VN/","refsource":"MISC","tags":[],"title":"[SECURITY] Fedora 38 Update: python-configobj-5.0.8-6.fc38 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"429"},{"url":"https://security.snyk.io/vuln/SNYK-PYTHON-CONFIGOBJ-3252494","name":"https://security.snyk.io/vuln/SNYK-PYTHON-CONFIGOBJ-3252494","refsource":"MISC","tags":[],"title":"Regular Expression Denial of Service (ReDoS) in configobj | CVE-2023-26112 | Snyk","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-26112","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26112","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"26112","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"configobj_project","cpe5":"configobj","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2023-26112","qid":"284636","title":"Fedora Security Update for python (FEDORA-2023-62baa45349)"},{"cve":"CVE-2023-26112","qid":"284637","title":"Fedora Security Update for python (FEDORA-2023-27b41bb133)"},{"cve":"CVE-2023-26112","qid":"285209","title":"Fedora Security Update for python (FEDORA-2023-64b2965699)"},{"cve":"CVE-2023-26112","qid":"355629","title":"Amazon Linux Security Advisory for python-configobj : ALAS2023-2023-254"},{"cve":"CVE-2023-26112","qid":"355770","title":"Amazon Linux Security Advisory for python-configobj : ALAS2-2023-2188"},{"cve":"CVE-2023-26112","qid":"673608","title":"EulerOS Security Update for python-configobj (EulerOS-SA-2024-1292)"},{"cve":"CVE-2023-26112","qid":"673628","title":"EulerOS Security Update for python-configobj (EulerOS-SA-2024-1094)"},{"cve":"CVE-2023-26112","qid":"673721","title":"EulerOS Security Update for python-configobj (EulerOS-SA-2024-1161)"},{"cve":"CVE-2023-26112","qid":"674101","title":"EulerOS Security Update for python-configobj (EulerOS-SA-2024-1070)"},{"cve":"CVE-2023-26112","qid":"674143","title":"EulerOS Security Update for python-configobj (EulerOS-SA-2024-1514)"},{"cve":"CVE-2023-26112","qid":"674155","title":"EulerOS Security Update for python-configobj (EulerOS-SA-2024-1493)"},{"cve":"CVE-2023-26112","qid":"691118","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for py39 (de970aef-d60e-466b-8e30-1ae945a047f1)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-26112","ASSIGNER":"report@snyk.io","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\\((.*)\\).\r\r**Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.\r\r"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Regular Expression Denial of Service (ReDoS)","cweId":"CWE-1333"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"configobj","version":{"version_data":[{"version_affected":"<","version_name":"0","version_value":"*"}]}}]}}]}},"references":{"reference_data":[{"url":"https://security.snyk.io/vuln/SNYK-PYTHON-CONFIGOBJ-3252494","refsource":"MISC","name":"https://security.snyk.io/vuln/SNYK-PYTHON-CONFIGOBJ-3252494"},{"url":"https://github.com/DiffSK/configobj/issues/232","refsource":"MISC","name":"https://github.com/DiffSK/configobj/issues/232"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZHY7B33EFY4LESP2NI4APQUPRROTAZK/","refsource":"MISC","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NZHY7B33EFY4LESP2NI4APQUPRROTAZK/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6BO4RLMYEJODCNUE3DJIIUUFVTPAG6VN/","refsource":"MISC","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6BO4RLMYEJODCNUE3DJIIUUFVTPAG6VN/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYU4IHVLOTYMFPH7KDOJGKZQR4GKWPFK/","refsource":"MISC","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYU4IHVLOTYMFPH7KDOJGKZQR4GKWPFK/"}]},"credits":[{"lang":"en","value":"DarkTinia"}],"impact":{"cvss":[{"version":"3.1","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P"}]}},"nvd":{"publishedDate":"2023-04-03 05:15:00","lastModifiedDate":"2023-11-07 04:09:00","problem_types":["CWE-1333"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:configobj_project:configobj:*:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}