Vulnerabilities
Vulnerable Software
Pygments:  >> Pygments  >> 1.3.1  Security Vulnerabilities
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVSS Score
5.5
EPSS Score
0.0
Published
2023-07-19
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.
CVSS Score
7.5
EPSS Score
0.023
Published
2021-03-17
The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
CVSS Score
9.0
EPSS Score
0.091
Published
2016-01-08


Contact Us

Shodan ® - All rights reserved