10 Total advisories
10 Vulnerabilities
0 Malware
Dependency scanning
Check whether pygments is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
LOW 3.3
CVE-2026-4539
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
LOW 3.3
CVE-2026-4539
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
UNKNOWN
CVE-2022-40896
CVE-2022-40896
MEDIUM 5.5
CVE-2022-40896
Pygments vulnerable to ReDoS
CRITICAL 9.0
CVE-2015-8557
Command Injection in Pygments
HIGH 7.5
CVE-2021-20270
Infinite Loop in Pygments
HIGH 7.5
CVE-2021-27291
Pygments vulnerable to Regular Expression Denial of Service (ReDoS)
UNKNOWN
CVE-2021-27291
CVE-2021-27291
UNKNOWN
CVE-2021-20270
CVE-2021-20270
UNKNOWN
CVE-2015-8557
CVE-2015-8557
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes