QID 980347
QID 980347: Python (pip) Security Update for Pygments (GHSA-9w8r-397f-prfh)
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9w8r-397f-prfh for updates pertaining to this vulnerability.
Vendor References
- GHSA-9w8r-397f-prfh -
github.com/advisories/GHSA-9w8r-397f-prfh
CVEs related to QID 980347
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9w8r-397f-prfh | Pygments |
|