VDB

DEBIAN-CVE-2026-4539

DEBIAN-CVE-2026-4539 PUBLISHED CVSS 3.299999952316284 LOW

A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Risk Scores

CVSS 3.1
3.299999952316284
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
Debian:11pygments2.13.0+dfsg, 2.12.0+dfsg-1~exp1, 2.12.0+dfsg-2
Debian:13pygments2.19.2+dfsg, 2.19.2+dfsg-1, 0
Debian:12pygments2.18.0+dfsg-2, 2.19.2+dfsg-1, *
Debian:14pygments2.18.0+dfsg, 0, 2.18.0+dfsg-2
Cloudflareaccess

Exploit Intelligence

…and 25 more exploits

Timeline

  • Mar 22, 2026 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›