Asymmetric denial of service - ReDoS In pygments
Description
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching A security flaw has been discovered in pygments before 2.20.0. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 2.20.0 | ||
debian 14 | - | ||
debian 11 | - | ||
rpm rhel10 | - | - | |
rpm rhel9 | - | - | |
debian 12 | - | ||
debian 13 | - |
Aliases
References