Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40092
HistoryApr 10, 2023 - 9:02 a.m.

Regular Expression Denial Of Service (ReDoS)

2023-04-1009:02:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
regular expression dos
software vulnerability
inefficient regex complexity

EPSS

0.001

Percentile

50.0%

configobj is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability is due to inefficent regex complexity via the validate function, which can lead to a Denial of Service if an attacker is able to control the input being parsed.