First published: Mon Nov 27 2023(Updated: )
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
Affected Software | Affected Version | How to fix |
---|---|---|
Pygments | <=2.15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2251643 is categorized as a ReDoS (Regular Expression Denial of Service) vulnerability.
Pygments versions up to and including 2.15.0 are affected by REDHAT-BUG-2251643.
To fix REDHAT-BUG-2251643, update Pygments to a version above 2.15.0.
REDHAT-BUG-2251643 impacts the SmithyLexer component in pygments/lexers/smithy.py.
There is currently no documented workaround for REDHAT-BUG-2251643; the best option is to update the library.