<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 08:22:54 +0000</lastBuildDate>
    <item>
      <title>BREW-scrapy-CVE-2026-55520 — Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching</title>
      <link>https://cve.radiocsirt.org/vuln/brew-scrapy-cve-2026-55520</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: scrapy&lt;/p&gt;
&lt;p&gt;### Problem description&lt;/p&gt;
&lt;p&gt;Protego constructs regular expressions to match URLs against `robots.txt` `Allow:` and `Disallow:` directives, see `protego._urlpattern._URLPattern._prepare_pattern_for_regex()`. Every `*` in the directive value is translated into a lazy `.*?` regex piece, thus a specially crafted directive value with many asterisks may produce a regex that freezes the parser due to exponential backtracking.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Parsing a specially crafted `robots.txt` with `protego.Protego.parse()` and then trying to match an URL with `protego.Protego.can_fetch()` results in the latter call not returning for a period dependent on the length of the URL.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```python
from protego import Protego&lt;/p&gt;
&lt;p&gt;robotstxt = f&amp;#34;&amp;#34;&amp;#34;
User-agent: *
Disallow: /{&amp;#34;*1&amp;#34; * 12}*Z
&amp;#34;&amp;#34;&amp;#34;
rp = Protego.parse(robotstxt)
url = &amp;#34;/&amp;#34; + &amp;#34;1&amp;#34; * 60
rp.can_fetch(url, &amp;#34;mybot&amp;#34;)  # freezes
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: scrapy&lt;/p&gt;
&lt;p&gt;### Problem description&lt;/p&gt;
&lt;p&gt;Protego constructs regular expressions to match URLs against `robots.txt` `Allow:` and `Disallow:` directives, see `protego._urlpattern._URLPattern._prepare_pattern_for_regex()`. Every `*` in the directive value is translated into a lazy `.*?` regex piece, thus a specially crafted directive value with many asterisks may produce a regex that freezes the parser due to exponential backtracking.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Parsing a specially crafted `robots.txt` with `protego.Protego.parse()` and then trying to match an URL with `protego.Protego.can_fetch()` results in the latter call not returning for a period dependent on the length of the URL.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```python
from protego import Protego&lt;/p&gt;
&lt;p&gt;robotstxt = f&amp;#34;&amp;#34;&amp;#34;
User-agent: *
Disallow: /{&amp;#34;*1&amp;#34; * 12}*Z
&amp;#34;&amp;#34;&amp;#34;
rp = Protego.parse(robotstxt)
url = &amp;#34;/&amp;#34; + &amp;#34;1&amp;#34; * 60
rp.can_fetch(url, &amp;#34;mybot&amp;#34;)  # freezes
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-scrapy-cve-2026-55520</guid>
    </item>
    <item>
      <title>EUVD-2026-362093</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362093</link>
      <description>EUVD-2026-362093</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362093</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55520</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55520</link>
      <description>&lt;p&gt;Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URLPattern._prepare_pattern_for_regex translates every asterisk in an Allow or Disallow directive into a lazy regular-expression wildcard, so a directive containing many asterisks creates exponential backtracking. After protego.Protego.parse processes a crafted robots.txt file, protego.Protego.can_fetch can spend an attacker-controlled period matching a near-miss URL and deny service to the crawler. The vulnerable path is src/protego/_urlpattern.py in the _URLPattern match logic. This issue is fixed in version 0.6.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URLPattern._prepare_pattern_for_regex translates every asterisk in an Allow or Disallow directive into a lazy regular-expression wildcard, so a directive containing many asterisks creates exponential backtracking. After protego.Protego.parse processes a crafted robots.txt file, protego.Protego.can_fetch can spend an attacker-controlled period matching a near-miss URL and deny service to the crawler. The vulnerable path is src/protego/_urlpattern.py in the _URLPattern match logic. This issue is fixed in version 0.6.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55520</guid>
    </item>
    <item>
      <title>GHSA-wjmf-p669-5m5p — Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wjmf-p669-5m5p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Protego&lt;/p&gt;
&lt;p&gt;### Problem description&lt;/p&gt;
&lt;p&gt;Protego constructs regular expressions to match URLs against `robots.txt` `Allow:` and `Disallow:` directives, see `protego._urlpattern._URLPattern._prepare_pattern_for_regex()`. Every `*` in the directive value is translated into a lazy `.*?` regex piece, thus a specially crafted directive value with many asterisks may produce a regex that freezes the parser due to exponential backtracking.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Parsing a specially crafted `robots.txt` with `protego.Protego.parse()` and then trying to match an URL with `protego.Protego.can_fetch()` results in the latter call not returning for a period dependent on the length of the URL.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```python
from protego import Protego&lt;/p&gt;
&lt;p&gt;robotstxt = f&amp;#34;&amp;#34;&amp;#34;
User-agent: *
Disallow: /{&amp;#34;*1&amp;#34; * 12}*Z
&amp;#34;&amp;#34;&amp;#34;
rp = Protego.parse(robotstxt)
url = &amp;#34;/&amp;#34; + &amp;#34;1&amp;#34; * 60
rp.can_fetch(url, &amp;#34;mybot&amp;#34;)  # freezes
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Protego&lt;/p&gt;
&lt;p&gt;### Problem description&lt;/p&gt;
&lt;p&gt;Protego constructs regular expressions to match URLs against `robots.txt` `Allow:` and `Disallow:` directives, see `protego._urlpattern._URLPattern._prepare_pattern_for_regex()`. Every `*` in the directive value is translated into a lazy `.*?` regex piece, thus a specially crafted directive value with many asterisks may produce a regex that freezes the parser due to exponential backtracking.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Parsing a specially crafted `robots.txt` with `protego.Protego.parse()` and then trying to match an URL with `protego.Protego.can_fetch()` results in the latter call not returning for a period dependent on the length of the URL.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```python
from protego import Protego&lt;/p&gt;
&lt;p&gt;robotstxt = f&amp;#34;&amp;#34;&amp;#34;
User-agent: *
Disallow: /{&amp;#34;*1&amp;#34; * 12}*Z
&amp;#34;&amp;#34;&amp;#34;
rp = Protego.parse(robotstxt)
url = &amp;#34;/&amp;#34; + &amp;#34;1&amp;#34; * 60
rp.can_fetch(url, &amp;#34;mybot&amp;#34;)  # freezes
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wjmf-p669-5m5p</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11202-1 — python313-Protego-0.6.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11202-1</link>
      <description>&lt;p&gt;python313-Protego-0.6.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-Protego-0.6.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11202-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3906 — Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3906</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: protego&lt;/p&gt;
&lt;p&gt;### Problem description&lt;/p&gt;
&lt;p&gt;Protego constructs regular expressions to match URLs against `robots.txt` `Allow:` and `Disallow:` directives, see `protego._urlpattern._URLPattern._prepare_pattern_for_regex()`. Every `*` in the directive value is translated into a lazy `.*?` regex piece, thus a specially crafted directive value with many asterisks may produce a regex that freezes the parser due to exponential backtracking.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Parsing a specially crafted `robots.txt` with `protego.Protego.parse()` and then trying to match an URL with `protego.Protego.can_fetch()` results in the latter call not returning for a period dependent on the length of the URL.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```python
from protego import Protego&lt;/p&gt;
&lt;p&gt;robotstxt = f&amp;#34;&amp;#34;&amp;#34;
User-agent: *
Disallow: /{&amp;#34;*1&amp;#34; * 12}*Z
&amp;#34;&amp;#34;&amp;#34;
rp = Protego.parse(robotstxt)
url = &amp;#34;/&amp;#34; + &amp;#34;1&amp;#34; * 60
rp.can_fetch(url, &amp;#34;mybot&amp;#34;)  # freezes
```&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: protego&lt;/p&gt;
&lt;p&gt;### Problem description&lt;/p&gt;
&lt;p&gt;Protego constructs regular expressions to match URLs against `robots.txt` `Allow:` and `Disallow:` directives, see `protego._urlpattern._URLPattern._prepare_pattern_for_regex()`. Every `*` in the directive value is translated into a lazy `.*?` regex piece, thus a specially crafted directive value with many asterisks may produce a regex that freezes the parser due to exponential backtracking.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Parsing a specially crafted `robots.txt` with `protego.Protego.parse()` and then trying to match an URL with `protego.Protego.can_fetch()` results in the latter call not returning for a period dependent on the length of the URL.&lt;/p&gt;
&lt;p&gt;### Proof of concept&lt;/p&gt;
&lt;p&gt;```python
from protego import Protego&lt;/p&gt;
&lt;p&gt;robotstxt = f&amp;#34;&amp;#34;&amp;#34;
User-agent: *
Disallow: /{&amp;#34;*1&amp;#34; * 12}*Z
&amp;#34;&amp;#34;&amp;#34;
rp = Protego.parse(robotstxt)
url = &amp;#34;/&amp;#34; + &amp;#34;1&amp;#34; * 60
rp.can_fetch(url, &amp;#34;mybot&amp;#34;)  # freezes
```&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3906</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-55520</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55520</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: python-protego, Ubuntu:22.04:LTS: python-protego, Ubuntu:24.04:LTS: python-protego, Ubuntu:25.10: python-protego, Ubuntu:26.04:LTS: python-protego&lt;/p&gt;
&lt;p&gt;Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URLPattern._prepare_pattern_for_regex translates every asterisk in an Allow or Disallow directive into a lazy regular-expression wildcard, so a directive containing many asterisks creates exponential backtracking. After protego.Protego.parse processes a crafted robots.txt file, protego.Protego.can_fetch can spend an attacker-controlled period matching a near-miss URL and deny service to the crawler. The vulnerable path is src/protego/_urlpattern.py in the _URLPattern match logic. This issue is fixed in version 0.6.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: python-protego, Ubuntu:22.04:LTS: python-protego, Ubuntu:24.04:LTS: python-protego, Ubuntu:25.10: python-protego, Ubuntu:26.04:LTS: python-protego&lt;/p&gt;
&lt;p&gt;Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URLPattern._prepare_pattern_for_regex translates every asterisk in an Allow or Disallow directive into a lazy regular-expression wildcard, so a directive containing many asterisks creates exponential backtracking. After protego.Protego.parse processes a crafted robots.txt file, protego.Protego.can_fetch can spend an attacker-controlled period matching a near-miss URL and deny service to the crawler. The vulnerable path is src/protego/_urlpattern.py in the _URLPattern match logic. This issue is fixed in version 0.6.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-55520</guid>
    </item>
  </channel>
</rss>
