Vulnerabilities (CVE)

Filtered by vendor Pygments Subscribe
Filtered by product Pygments
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-20270 3 Fedoraproject, Pygments, Redhat 6 Fedora, Pygments, Enterprise Linux and 3 more 2021-10-20 5.0 MEDIUM 7.5 HIGH
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
CVE-2021-27291 1 Pygments 1 Pygments 2021-05-06 5.0 MEDIUM 7.5 HIGH
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.
CVE-2015-8557 2 Canonical, Pygments 2 Ubuntu Linux, Pygments 2017-07-01 9.3 HIGH 9.0 CRITICAL
The FontManager._get_nix_font_path function in formatters/ in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.