CVE-2022-40896Unrestricted File Upload in Pygments

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 79.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 19
Latest updateApr 1

Description

A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

debiandebian/pygments< pygments 2.15.1+dfsg-1 (forky)
PyPIpygments/pygments< 2.15.0
Debianpygments/pygments< 2.15.1+dfsg-1+1
NVDpygments/pygments2.15.0

Patches

🔴Vulnerability Details

5
OSV
c2cciutils affected by CVE-2022-408962026-04-01
GHSA
c2cciutils affected by CVE-2022-408962026-04-01
OSV
CVE-2022-40896: A ReDoS issue was discovered in pygments/lexers/smithy2023-07-19
GHSA
Pygments vulnerable to ReDoS2023-07-19
OSV
Pygments vulnerable to ReDoS2023-07-19

📋Vendor Advisories

6
Ubuntu
Pygments vulnerability2024-11-26
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Pygments) — CVE-2022-408962024-04-15
Oracle
Oracle Oracle Utilities Applications Risk Matrix: NMS Monitor (Pygments) — CVE-2022-408962024-01-15
Red Hat
pygments: ReDoS in pygments2023-11-26
Microsoft
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.2023-07-11
CVE-2022-40896 — Unrestricted File Upload in Pygments | cvebase