CVE-2023-26112: Configobj Project Configobj
Medium severity, CVSS 5.9. EPSS: 1.3% chance of exploitation in the next 30 days.
All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). **Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.
Affected products
- Configobj Project Configobj: any version
Published 2023-04-03. Last modified 2026-06-17.