First published: Wed Jul 19 2023(Updated: )
A ReDoS issue was discovered in `pygments/lexers/smithy.py` in Pygments until 2.15.0 via SmithyLexer.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pygments Pygments | <=2.15.0 | |
pip/Pygments | <2.15.0 | 2.15.0 |
debian/pygments | <=2.7.1+dfsg-2.1<=2.14.0+dfsg-1 | 2.18.0+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-40896 is medium with a CVSS score of 5.5.
Pygments versions up to and including 2.15.0 are affected by CVE-2022-40896.
CVE-2022-40896 is a ReDoS (Regular Expression Denial of Service) vulnerability discovered in the `pygments/lexers/smithy.py` file in Pygments, impacting versions until 2.15.0 via the SmithyLexer.
To mitigate CVE-2022-40896, it is recommended to update Pygments to version 2.15.0.
You can find more information about CVE-2022-40896 on the following references: [Link 1](https://pypi.org/project/Pygments/), [Link 2](https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages-part-2/), [Link 3](https://github.com/pygments/pygments/blob/master/pygments/lexers/smithy.py#L61).