Skip to main content

Inefficient Regular Expression Complexity

CVE-2022-40896

Severity Medium
Score 5.5/10

Summary

A ReDoS issue was discovered in 'smithy.py', 'templates.py' and 'configs.py' in Pygments versions through 2.15.0.

  • LOW
  • LOCAL
  • NONE
  • UNCHANGED
  • REQUIRED
  • NONE
  • NONE
  • HIGH

CWE-1333 - Inefficient Regular Expression Complexity

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Advisory Timeline

  • Published