Releases11
Frequency1 year 3 weeks
Last Release
Stars339
Python 3+ compatible port of the configobj library

CVE History

CVEPublishedCVSS v3CVSS v2
3.7 LOW

All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). **Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.