CVE-2026-4539: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-4539 is a Regular Expression Denial of Service (ReDoS) vulnerability in the Pygments syntax highlighting library, specifically in the AdlLexer function within pygments/lexers/archetype.py. The flaw affects Pygments versions up to and including 2.19.2 (confirmed affected: 2.19.0, 2.19.1, 2.19.2). It was reported via a GitHub issue on March 7, 2026, and publicly disclosed on March 22, 2026. The vulnerability carries a CVSS v3.1 base score of 3.3 (Low) and a CVSS v4.0 base score of 4.8 (Medium) (Red Hat Advisory, GitHub Issue).

Technical details

The root cause is an inefficient regular expression pattern at line 296 of pygments/lexers/archetype.py, classified under CWE-400 (Uncontrolled Resource Consumption) and CWE-1333 (Inefficient Regular Expression Complexity). The vulnerable regex (\d|[a-fA-F])+(-( \d|[a-fA-F])+){3,}, intended for GUID matching, contains nested repeating quantifiers that cause catastrophic backtracking when processing specially crafted input. An attacker with local access can trigger this by passing a malicious string — such as 10,000 consecutive 'A' characters followed by a hyphen — to the AdlLexer and invoking the lex function, causing processing times of approximately 8 seconds for a ~10,001-character input. A public proof-of-concept demonstrating the exploit is available in the GitHub issue report (GitHub Issue, Red Hat Bugzilla).

Impact

Successful exploitation causes a Denial of Service (DoS) condition through excessive CPU consumption, potentially blocking the application thread indefinitely with sufficiently large malicious input. The impact is limited to availability (no confidentiality or integrity impact), and exploitation requires local access with low privileges. In environments where Pygments processes arbitrary user-supplied input (e.g., web services, code editors, documentation platforms), this could be leveraged to exhaust server resources and cause service unavailability (GitHub Issue, Red Hat Advisory).

Exploitability

A public proof-of-concept exploit has been released and is available in the GitHub issue tracker. The EPSS score is approximately 0.013% (0.000130), indicating a low probability of widespread exploitation. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVSS v4.0 exploit maturity is rated as "Proof of Concept" (GitHub Issue, Red Hat Advisory).

Exploitation steps

  1. Identify target: Locate a system or application running Pygments version ≤ 2.19.2 that processes user-supplied input through the AdlLexer (used for Archetype/ADL syntax highlighting).
  2. Craft malicious input: Construct a string designed to trigger catastrophic backtracking in the GUID-matching regex — for example, "A" * 10000 + "-" (10,000 'A' characters followed by a hyphen).
  3. Trigger the vulnerable code path: Pass the malicious input to the AdlLexer and invoke the lex function, e.g.:
from pygments.lexers import AdlLexer
from pygments import lex
malicious_input = "A" * 10000 + "-"
lexer = AdlLexer()
list(lex(malicious_input, lexer))
  1. Observe DoS: The regex engine enters catastrophic backtracking, consuming excessive CPU for approximately 8+ seconds per invocation for the test input, potentially blocking the application thread or exhausting server resources if called repeatedly (GitHub Issue).

Indicators of compromise

  • Process: Unusual sustained high CPU usage by Python processes running Pygments, particularly those invoking AdlLexer; processes hanging or taking abnormally long to complete syntax highlighting tasks.
  • Logs: Application logs showing timeouts or slow response times correlated with syntax highlighting requests; error logs indicating thread blocking or resource exhaustion in services using Pygments.
  • File System: Presence of Pygments version ≤ 2.19.2 installed (check via pip show pygments); specifically the unpatched pygments/lexers/archetype.py containing the vulnerable regex at line 296.

Mitigation and workarounds

Upgrade Pygments to version 2.20.0 or later, which was released on March 29, 2026, and addresses this vulnerability (Pygments Releases). As a workaround where upgrading is not immediately possible, restrict local user access and avoid exposing Pygments-based services to untrusted input; implement process timeouts to terminate long-running Pygments operations. IBM has issued advisories for affected products including watsonx Code Assistant, Maximo Application Suite (Monitor and Visual Inspection components), IBM Process Mining, and IBM Guardium Data Security Center, and recommends updating the bundled Pygments dependency (IBM Advisory, IBM Process Mining). SUSE has also released a security update (SUSE-SU-2026:1667-1) for python-pygments (SUSE Advisory).

Community reactions

Red Hat tracked the issue as low severity in their Bugzilla system, with the bug remaining in NEW status as of early June 2026, indicating no immediate patch planned for Red Hat products (Red Hat Bugzilla). IBM issued multiple security bulletins for affected enterprise products, reflecting the broad downstream impact of the vulnerability on products bundling Pygments (IBM Advisory). The Pygments project's own documentation acknowledges that guaranteeing execution time bounds is practically impossible and recommends implementing process timeouts as a general mitigation strategy (Pygments GitHub). SUSE and openSUSE issued security updates, and the vulnerability received coverage from Linux security news outlets (SUSE Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pygments

Affected

sid

pygments: 2.20.0+dfsg-1

Fixed

trixie

pygments

Affected

Ubuntu

Unknown

bionic (esm-infra)

pygments

Unknown

devel

pygments

Unknown

focal (esm-infra)

pygments

Unknown

jammy

pygments

Unknown

noble

pygments

Unknown

resolute

pygments

Unknown

trusty (esm-infra-legacy)

pygments

Unknown

xenial (esm-infra-legacy)

pygments

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management