Vulnerability Description
Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URLPattern._prepare_pattern_for_regex translates every asterisk in an Allow or Disallow directive into a lazy regular-expression wildcard, so a directive containing many asterisks creates exponential backtracking. After protego.Protego.parse processes a crafted robots.txt file, protego.Protego.can_fetch can spend an attacker-controlled period matching a near-miss URL and deny service to the crawler. The vulnerable path is src/protego/_urlpattern.py in the _URLPattern match logic. This issue is fixed in version 0.6.2.
Related Weaknesses (CWE)
References
- https://github.com/scrapy/protego/commit/785940181659bf440ba82f1da148fade5087e85
- https://github.com/scrapy/protego/releases/tag/0.6.2
- https://github.com/scrapy/protego/security/advisories/GHSA-wjmf-p669-5m5p
FAQ
What is CVE-2026-55520?
CVE-2026-55520 is a documented vulnerability. Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URLPattern._prepare_pattern_for_regex translates every asterisk in an Allow or Disa...
How severe is CVE-2026-55520?
CVSS scoring is not yet available for CVE-2026-55520. Check NVD for updates.
Is there a patch for CVE-2026-55520?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.