GHSA-wjmf-p669-5m5p

    Dashboard / Vulnerabilities / GHSA-wjmf-p669-5m5p

    GHSA-wjmf-p669-5m5p

    Published: 28 Aug 2026Last Modified: 28 Aug 2026

    Summary: Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

    Details: ### Problem description Protego constructs regular expressions to match URLs against `robots.txt` `Allow:` and `Disallow:` directives, see `protego._urlpattern._URLPattern._prepare_pattern_for_regex()`. Every `*` in the directive value is translated into a lazy `.*?` regex piece, thus a specially crafted directive value with many asterisks may produce a regex that freezes the parser due to exponential backtracking. ### Impact Parsing a specially crafted `robots.txt` with `protego.Protego.parse()` and then trying to match an URL with `protego.Protego.can_fetch()` results in the latter call not returning for a period dependent on the length of the URL. ### Proof of concept ```python from protego import Protego robotstxt = f""" User-agent: * Disallow: /{"*1" * 12}*Z """ rp = Protego.parse(robotstxt) url = "/" + "1" * 60 rp.can_fetch(url, "mybot") # freezes ```

    Affected packages

    Package

    Name: protego

    Purl: pkg:pypi/protego

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.6.2

    Affected versions

    0.1
    0.1.12
    0.1.14
    0.1.15
    0.1.16
    0.1.dev0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High