VDB
CVE-2026-4539
CVE-2026-4539
PUBLISHED
CVSS 4.800000190734863 MEDIUM
A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
EPSS 0.01% · 0.7th percentile
Risk Scores
CVSS v4.0
4.800000190734863
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
EPSS Score
0.01%
0.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | Pygments | 0, 0, 0 |
| n/a | pygments | 2.19.0, 2.19.1, 2.19.2 |
Timeline
- Mar 22, 2026 CVE Published
- Mar 22, 2026 EPSS Score
- Mar 22, 2026 Coalition ESS Score
- Mar 22, 2026 PoC Published
- Mar 23, 2026 EPSS Score
- Mar 24, 2026 EPSS Score
- Mar 25, 2026 EPSS Score
- Mar 25, 2026 Security Advisory
- Mar 26, 2026 EPSS Score
- Mar 26, 2026 PoC Published
- Mar 26, 2026 PoC Published
- Mar 30, 2026 CVE Updated
References
- VDB-352327 | pygments archetype.py AdlLexer redos vdb
- VDB-352327 | CTI Indicators (IOB, IOC, TTP, IOA) url
- Submit #774685 | pygments <=2.19.2 Denial of Service third-party-advisory
- https://github.com/pygments/pygments/issues/3058 exploit
- https://github.com/pygments/pygments/ url
- https://nvd.nist.gov/vuln/detail/CVE-2026-4539 advisory
- https://github.com/pygments/pygments package
- https://github.com/pygments/pygments/pull/3064 url
- https://github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc url
- https://github.com/pygments/pygments/releases/tag/2.20.0 url
- https://www.ibm.com/support/pages/node/7271707 advisory
- https://www.ibm.com/support/pages/node/7271922 advisory
- https://www.ibm.com/support/pages/node/7271681 advisory
- https://www.ibm.com/support/pages/node/7271765 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37451 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37445 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37460 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37449 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37450 advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37466 advisory
…and 12 more