๐Ÿ” CVE Alert

CVE-2026-55520

UNKNOWN 0.0

Protego: Exponential backtracking ReDoS in robots.txt URL wildcard matching

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URLPattern._prepare_pattern_for_regex translates every asterisk in an Allow or Disallow directive into a lazy regular-expression wildcard, so a directive containing many asterisks creates exponential backtracking. After protego.Protego.parse processes a crafted robots.txt file, protego.Protego.can_fetch can spend an attacker-controlled period matching a near-miss URL and deny service to the crawler. The vulnerable path is src/protego/_urlpattern.py in the _URLPattern match logic. This issue is fixed in version 0.6.2.

CWE CWE-400 CWE-1333
Vendor scrapy
Product protego
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for scrapy protego

Be the first to know when new unknown vulnerabilities affecting scrapy protego are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

scrapy / protego
< 0.6.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/scrapy/protego/security/advisories/GHSA-wjmf-p669-5m5p github.com: https://github.com/scrapy/protego/commit/785940181659bf440ba82f1da148fade5087e858 github.com: https://github.com/scrapy/protego/releases/tag/0.6.2