CVE-2021-27291
published 2021-03-17CVE-2021-27291: In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.91%
89.1th percentile
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mediawiki | < mediawiki 1:1.35.2-1 (bookworm) | mediawiki 1:1.35.2-1 (bookworm) |
| debian | pygments | < mediawiki 1:1.35.2-1 (bookworm) | mediawiki 1:1.35.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| mediawiki | mediawiki | >= 0 < 1:1.35.2-1 | 1:1.35.2-1 |
| msrc | azl3_python-pygments_2.5.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-pygments_2.7.4-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| pygments | pygments | >= 0 < 2.7.1+dfsg-2.1 | 2.7.1+dfsg-2.1 |
| pygments | pygments | >= 0 < 2.7.1+dfsg-2.1 | 2.7.1+dfsg-2.1 |
| pygments | pygments | >= 0 < 2.7.1+dfsg-2.1 | 2.7.1+dfsg-2.1 |
| pygments | pygments | >= 0 < 2.7.1+dfsg-2.1 | 2.7.1+dfsg-2.1 |
| pygments | pygments | >= 0 < 1.6+dfsg-1ubuntu1.1+esm1 | 1.6+dfsg-1ubuntu1.1+esm1 |
| pygments | pygments | >= 1.1 < 2.7.4 | 2.7.4 |
| pygments | pygments | >= 1.1 < 2.7.4 | 2.7.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pygments vulnerabilities
vendor_ubuntu·2023-08-14·CVSS 7.5
CVE-2021-20270 [HIGH] Pygments vulnerabilities
Title: Pygments vulnerabilities
Summary: Pygments could be made to hang if it opened a specially crafted file.
USN-4897-1 fixed several vulnerabilities in Pygments. This update provides
the corresponding update for Ubuntu 14.04 LTS.
Original advisory details:
Ben Caller discovered that Pygments incorrectly handled parsing certain
files. If a user or automated system were tricked into parsing a specially
crafted file, a remote attacker could cause Pygments to hang or consume
resources, resulting in a denial of service. (CVE-2021-27291)
It was discovered that Pygments incorrectly handled parsing certain
files. An attacker could possibly use this issue to cause a denial of
service. (CVE-2021-20270)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Pygments vulnerability
vendor_ubuntu·2021-03-30
CVE-2021-27291 Pygments vulnerability
Title: Pygments vulnerability
Summary: Pygments could be made to hang if it opened a specially crafted file.
Ben Caller discovered that Pygments incorrectly handled parsing certain
files. If a user or automated system were tricked into parsing a specially
crafted file, a remote attacker could cause Pygments to hang or consume
resources, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
In pygments 1.1+ fixed in 2.7.4 the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and
vendor_msrc·2021-03-09·CVSS 7.5
CVE-2021-27291 [HIGH] CWE-1333 In pygments 1.1+ fixed in 2.7.4 the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and
In pygments 1.1+ fixed in 2.7.4 the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input an attacker can cause a denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blo
Red Hat
python-pygments: ReDoS in multiple lexers
vendor_redhat·2021-01-11·CVSS 7.5
CVE-2021-27291 [HIGH] CWE-400 python-pygments: ReDoS in multiple lexers
python-pygments: ReDoS in multiple lexers
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.
A denial of service attack was discovered against pygments. Some of the regular expressions used to tokenise source code for highlighting have exponential complexity. A specially crafted input file could cause pygments to take effectively infinite time to parse, consuming CPU resources and denying access to the service.
Package: python-pygments (Red Hat Enterprise Linux 6) - Out of support scope
Package: python-pygments (Red Hat Enterprise Linux 7) -
Debian
CVE-2021-27291: mediawiki - In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages...
vendor_debian·2021·CVSS 7.5
CVE-2021-27291 [HIGH] CVE-2021-27291: mediawiki - In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages...
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1:1.35.2-1)
bullseye: resolved (fixed in 1:1.35.2-1)
forky: resolved (fixed in 1:1.35.2-1)
sid: resolved (fixed in 1:1.35.2-1)
trixie: resolved (fixed in 1:1.35.2-1)
OSV
pygments vulnerabilities
osv·2023-08-14·CVSS 7.5
CVE-2021-27291 [HIGH] pygments vulnerabilities
pygments vulnerabilities
USN-4897-1 fixed several vulnerabilities in Pygments. This update provides
the corresponding update for Ubuntu 14.04 LTS.
Original advisory details:
Ben Caller discovered that Pygments incorrectly handled parsing certain
files. If a user or automated system were tricked into parsing a specially
crafted file, a remote attacker could cause Pygments to hang or consume
resources, resulting in a denial of service. (CVE-2021-27291)
It was discovered that Pygments incorrectly handled parsing certain
files. An attacker could possibly use this issue to cause a denial of
service. (CVE-2021-20270)
OSV
Pygments vulnerable to Regular Expression Denial of Service (ReDoS)
osv·2021-03-29
CVE-2021-27291 [HIGH] Pygments vulnerable to Regular Expression Denial of Service (ReDoS)
Pygments vulnerable to Regular Expression Denial of Service (ReDoS)
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.
GHSA
Pygments vulnerable to Regular Expression Denial of Service (ReDoS)
ghsa·2021-03-29
CVE-2021-27291 [HIGH] CWE-400 Pygments vulnerable to Regular Expression Denial of Service (ReDoS)
Pygments vulnerable to Regular Expression Denial of Service (ReDoS)
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.
OSV
CVE-2021-27291: In pygments 1
osv·2021-03-17·CVSS 7.5
CVE-2021-27291 [HIGH] CVE-2021-27291: In pygments 1
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gist.github.com/b-c-ds/b1a2cc0c68a35c57188575eb496de5cehttps://github.com/pygments/pygments/commit/2e7e8c4a7b318f4032493773732754e418279a14https://lists.debian.org/debian-lts-announce/2021/03/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2021/05/msg00003.htmlhttps://lists.debian.org/debian-lts-announce/2021/05/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GSJRFHALQ7E3UV4FFMFU2YQ6LUDHAI55/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WSLD67LFGXOX2K5YNESSWAS4AGZIJTUQ/https://www.debian.org/security/2021/dsa-4878https://www.debian.org/security/2021/dsa-4889https://gist.github.com/b-c-ds/b1a2cc0c68a35c57188575eb496de5cehttps://github.com/pygments/pygments/commit/2e7e8c4a7b318f4032493773732754e418279a14https://lists.debian.org/debian-lts-announce/2021/03/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2021/05/msg00003.htmlhttps://lists.debian.org/debian-lts-announce/2021/05/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GSJRFHALQ7E3UV4FFMFU2YQ6LUDHAI55/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WSLD67LFGXOX2K5YNESSWAS4AGZIJTUQ/https://www.debian.org/security/2021/dsa-4878https://www.debian.org/security/2021/dsa-4889
2021-03-17
Published