CVE-2026-55520: Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
Parsing a specially crafted robots.txt with protego.Protego.parse() and then trying to match an URL with protego.Protego.can_fetch() results in the latter call not returning for a period dependent on the length of the URL.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55520 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →