CVE-2026-4539 describes a low-severity vulnerability in pygments versions up to 2.19.2, specifically within the AdlLexer function, which can lead to inefficient regular expression complexity (ReDoS). Exploitation requires local access and user privileges, potentially causing a denial of service due to resource exhaustion. Although a public exploit has been released, there is no indication of active exploitation, and community discussion or media coverage regarding this flaw is currently absent.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Pygments | 2.19.0, 2.19.1, 2.19.2CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.