A high severity vulnerability, CVE-2026-55520 with a CVSS score of 7.1, affects Protego where an attacker can cause the parser to freeze due to exponential backtracking in robots.txt URL wildcard matching, allowing them to conduct denial-of-service attacks. This issue arises from the fact that Protego constructs regular expressions to match URLs against `robots.txt` directives and a specially crafted directive value with many asterisks may produce a regex that freezes the parser. The vulnerability is present in versions of Protego prior to 0.6.2, specifically affecting Protego versions up to and including 0.6.1. The flaw type is CWE-400 and CWE-1333, with an attack vector of network access, requiring no privileges or user interaction. The business impact includes the potential for denial-of-service attacks, which can result in significant downtime and financial losses.
We recommend you to update Protego to version 0.6.2.[/subscribe_to_unlock_form]
A high severity vulnerability, CVE-2026-55520 with a CVSS score of 7.1, affects Protego where an attacker can cause the parser to freeze due to exponential backtracking in robots.txt URL wildcard matching, allowing them to conduct denial-of-service attacks. This issue arises from the fact that Protego constructs regular expressions to match URLs against `robots.txt` directives and a specially crafted directive value with many asterisks may produce a regex that freezes the parser. The vulnerability is present in versions of Protego prior to 0.6.2, specifically affecting Protego versions up to and including 0.6.1. The flaw type is CWE-400 and CWE-1333, with an attack vector of network access, requiring no privileges or user interaction. The business impact includes the potential for denial-of-service attacks, which can result in significant downtime and financial losses.
We recommend you to update Protego to version 0.6.2.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]