skip to content
Back to
Home Bounties Research Advisories CodeQL Wall of Fame Get Involved Events
August 12, 2022

GHSL-2021-111: ReDoS (Regular Expression Denial of Service) in Dependency Parser - CVE-2022-39280

GitHub Security Lab

Coordinated Disclosure Timeline


Dependency Parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service).


Dependency Parser

Tested Version



ReDoS, or Regular Expression Denial of Service, is a vulnerability affecting inefficient regular expressions which can perform extremely badly when run on a crafted input string.

This vulnerability was found using a CodeQL query which identifies inefficient regular expressions.


The vulnerable regular expression is here.

Please follow these steps to reproduce the issue:

from dparse import parse, filetypes

content = """

df = parse(content, file_type=filetypes.requirements_txt)


This issue may lead to a denial of service.


This issue was discovered by GitHub team members @erik-krogh (Erik Krogh Kristensen) and @yoff (Rasmus Petersen).


You can contact the GHSL team at, please include a reference to GHSL-2021-111 in any communication regarding this issue.