$npx skillfedfor your agent

regexploit

Find regular expressions vulnerable to ReDoS

With conditionsPyPI SecurityReleased Mar 2021334.1K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — regexploit-1.0.0-py3-none-any.whl
v1.0.0 · released 2021-03-11 · Python >=3.8

Yes, if you work with untrusted regex patterns or need to audit code for ReDoS vulnerabilities. The tool is lightweight, has no dependencies, and fills a specific security niche. However, maintenance is dormant (last release March 2021), so treat it as a stable utility rather than an actively developed project. Not necessary for typical development workflows that don't expose regex engines to adversarial input.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.8 or later.
  • NodeJS 12+ is required only if extracting regexes from JavaScript/TypeScript code.
  • Low install friction with no runtime dependencies.

License · maintenance · safety

permissive license (permissive) — Licensed under Apache 2.0 (permissive), allowing free use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.

last release 2021-03-11 (1982 days) · last repo commit 2024-02-09 · 848 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 334,127 downloads/mo, #7,494 on PyPI

Verify before relying

pip install regexploit

regexploit
# Enter regex at prompt, e.g.: v\w*_\w*_\w*$
# Output shows worst-case complexity and example malicious input

# Or scan installed Python modules:
regexploit-python-env
  • Whether the tool's ReDoS detection algorithm covers all known ReDoS patterns or has documented limitations.
  • Performance characteristics when analyzing very large regex collections or complex patterns.
Same gist for agents: .md · .json

What it is and what it does

Regexploit is a command-line security scanner that detects regular expressions vulnerable to ReDoS (Regular Expression Denial of Service) attacks. It analyzes regex patterns to determine their worst-case backtracking complexity and generates concrete malicious input strings that trigger catastrophic backtracking, causing the regex engine to hang or consume excessive CPU.

The tool operates in multiple modes: interactive (stdin), batch file processing, and automatic extraction from Python, JavaScript, TypeScript, C#, JSON, and YAML source files. It can also scan all compiled regexes in an installed Python environment. For each vulnerable pattern found, it reports the complexity level (cubic, exponential, etc.), identifies the repeated character causing the issue, and provides a concrete exploit string. The package has been used to identify ReDoS vulnerabilities in production libraries including CPython's urllib, Pillow, httplib2, and ua-parser.

Use it for

  • Scan your codebase before deployment to find regexes that could be exploited by attackers sending crafted input.
  • Audit third-party Python packages installed in your environment for known ReDoS vulnerabilities.
  • Validate regex patterns during code review to catch performance regressions before they reach production.
  • Generate proof-of-concept exploit strings to demonstrate ReDoS impact to stakeholders or for security testing.
  • Analyze JavaScript/TypeScript regex patterns in Node.js projects for denial-of-service risks.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you work with untrusted regex patterns or need to audit code for ReDoS vulnerabilities.

The tool is lightweight, has no dependencies, and fills a specific security niche. However, maintenance is dormant (last release March 2021), so treat it as a stable utility rather than an actively developed project. Not necessary for typical development workflows that don't expose regex engines to adversarial input.

Install

regexploit on PyPI

Before you install

Low install friction with no runtime dependencies. The package is dormant (last release March 2021, last commit February 2024), so maintenance is minimal; it remains functional for its narrow purpose but receives no active development.

Requires Python 3.8 or later. NodeJS 12+ is required only if extracting regexes from JavaScript/TypeScript code.

License in practice

Licensed under Apache 2.0 (permissive), allowing free use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.

Quickstart

pip install regexploit

regexploit
# Enter regex at prompt, e.g.: v\w*_\w*_\w*$
# Output shows worst-case complexity and example malicious input

# Or scan installed Python modules:
regexploit-python-env

Verify before relying

  • Whether the tool's ReDoS detection algorithm covers all known ReDoS patterns or has documented limitations.
  • Performance characteristics when analyzing very large regex collections or complex patterns.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.8
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceDormant 1,982 days since the last release
Last repo commit
First released
Downloads334,127 / month, #7,494 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3

Evidence: regexploit-1.0.0-py3-none-any.whl

Tags

Capabilities
regex denial of service detectionredos vulnerability scannerregular expression backtracking analysisfind vulnerable regexesregex security testingcatastrophic backtracking finderpattern complexity analyzer
Topics
security-auditregex-analysisdenial-of-service

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “regex denial of service detection”

  • regexploitRegexploit analyzes regular expressions to identify those vulnerable…
  • carelyticsCarelytics provides healthcare data cleaning, validation, and…
  • interegularInteregular checks whether pairs of Python regular expressions can…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also iregexp-check · real-regex · greenery · interegular · multiregex · backrefs · repath · regress · re-assert · exrex