
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4539 is a Regular Expression Denial of Service (ReDoS) vulnerability in the Pygments syntax highlighting library, specifically in the AdlLexer function within pygments/lexers/archetype.py. The flaw affects Pygments versions up to and including 2.19.2 (confirmed affected: 2.19.0, 2.19.1, 2.19.2). It was reported via a GitHub issue on March 7, 2026, and publicly disclosed on March 22, 2026. The vulnerability carries a CVSS v3.1 base score of 3.3 (Low) and a CVSS v4.0 base score of 4.8 (Medium) (Red Hat Advisory, GitHub Issue).
The root cause is an inefficient regular expression pattern at line 296 of pygments/lexers/archetype.py, classified under CWE-400 (Uncontrolled Resource Consumption) and CWE-1333 (Inefficient Regular Expression Complexity). The vulnerable regex (\d|[a-fA-F])+(-( \d|[a-fA-F])+){3,}, intended for GUID matching, contains nested repeating quantifiers that cause catastrophic backtracking when processing specially crafted input. An attacker with local access can trigger this by passing a malicious string — such as 10,000 consecutive 'A' characters followed by a hyphen — to the AdlLexer and invoking the lex function, causing processing times of approximately 8 seconds for a ~10,001-character input. A public proof-of-concept demonstrating the exploit is available in the GitHub issue report (GitHub Issue, Red Hat Bugzilla).
Successful exploitation causes a Denial of Service (DoS) condition through excessive CPU consumption, potentially blocking the application thread indefinitely with sufficiently large malicious input. The impact is limited to availability (no confidentiality or integrity impact), and exploitation requires local access with low privileges. In environments where Pygments processes arbitrary user-supplied input (e.g., web services, code editors, documentation platforms), this could be leveraged to exhaust server resources and cause service unavailability (GitHub Issue, Red Hat Advisory).
A public proof-of-concept exploit has been released and is available in the GitHub issue tracker. The EPSS score is approximately 0.013% (0.000130), indicating a low probability of widespread exploitation. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The CVSS v4.0 exploit maturity is rated as "Proof of Concept" (GitHub Issue, Red Hat Advisory).
AdlLexer (used for Archetype/ADL syntax highlighting)."A" * 10000 + "-" (10,000 'A' characters followed by a hyphen).AdlLexer and invoke the lex function, e.g.:from pygments.lexers import AdlLexer
from pygments import lex
malicious_input = "A" * 10000 + "-"
lexer = AdlLexer()
list(lex(malicious_input, lexer))AdlLexer; processes hanging or taking abnormally long to complete syntax highlighting tasks.pip show pygments); specifically the unpatched pygments/lexers/archetype.py containing the vulnerable regex at line 296.Upgrade Pygments to version 2.20.0 or later, which was released on March 29, 2026, and addresses this vulnerability (Pygments Releases). As a workaround where upgrading is not immediately possible, restrict local user access and avoid exposing Pygments-based services to untrusted input; implement process timeouts to terminate long-running Pygments operations. IBM has issued advisories for affected products including watsonx Code Assistant, Maximo Application Suite (Monitor and Visual Inspection components), IBM Process Mining, and IBM Guardium Data Security Center, and recommends updating the bundled Pygments dependency (IBM Advisory, IBM Process Mining). SUSE has also released a security update (SUSE-SU-2026:1667-1) for python-pygments (SUSE Advisory).
Red Hat tracked the issue as low severity in their Bugzilla system, with the bug remaining in NEW status as of early June 2026, indicating no immediate patch planned for Red Hat products (Red Hat Bugzilla). IBM issued multiple security bulletins for affected enterprise products, reflecting the broad downstream impact of the vulnerability on products bundling Pygments (IBM Advisory). The Pygments project's own documentation acknowledges that guaranteeing execution time bounds is practically impossible and recommends implementing process timeouts as a general mitigation strategy (Pygments GitHub). SUSE and openSUSE issued security updates, and the vulnerability received coverage from Linux security news outlets (SUSE Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."