Bugzilla – Bug 1213505
VUL-0: CVE-2022-40896: python-Pygments: A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
Last modified: 2023-07-21 14:39:59 UTC
CVE-2022-40896 A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-40896 https://www.cve.org/CVERecord?id=CVE-2022-40896 https://github.com/pygments/pygments/blob/master/pygments/lexers/smithy.py#L61 https://pypi.org/project/Pygments/ https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages-part-2/
According to PyUP (https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages-part-2/), the issue is fixed by three individual commits: - https://github.com/pygments/pygments/commit/dd52102c38ebe78cd57748e09f38929fd283ad04 - https://github.com/pygments/pygments/pull/2404/commits/ce60712292e5734c44700eba16c0f3af5c298390 - https://github.com/pygments/pygments/commit/97eb3d5ec7c1b3ea4fcf9dee30a2309cf92bd194 These patches do not apply as is to the Pygments versions found in SLE-15.