HIGH 7.5 PyPI

Pygments vulnerable to Regular Expression Denial of Service (ReDoS)

GHSA-pq64-v7f5-gqh8 · CVE-2021-27291 · PYSEC-2021-141

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.

Ready to move

Start Securing

Free, no credit card | First findings in minutes