CVE-2022-40896: Malicious File Upload
A ReDoS issue was discovered in pygments/lexers/smithy.py in Pygments until 2.15.0 via SmithyLexer.
Other sources
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/Pygmentsto a version that resolves this vulnerability.Fixed in 2.15.0 - Upgrade
Upgrade
debian/pygmentsto a version that resolves this vulnerability.Fixed in 2.18.0+dfsg-1 - Upgrade
Upgrade
pygmentsto a version that resolves this vulnerability.Fixed in 2.15.0
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40896?
The severity of CVE-2022-40896 is medium with a CVSS score of 5.5.
Which software versions are affected by CVE-2022-40896?
Pygments versions up to and including 2.15.0 are affected by CVE-2022-40896.
What is the vulnerability description of CVE-2022-40896?
CVE-2022-40896 is a ReDoS (Regular Expression Denial of Service) vulnerability discovered in the `pygments/lexers/smithy.py` file in Pygments, impacting versions until 2.15.0 via the SmithyLexer.
How can I mitigate CVE-2022-40896?
To mitigate CVE-2022-40896, it is recommended to update Pygments to version 2.15.0.
Where can I find more information about CVE-2022-40896?
You can find more information about CVE-2022-40896 on the following references: [Link 1](https://pypi.org/project/Pygments/), [Link 2](https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages-part-2/), [Link 3](https://github.com/pygments/pygments/blob/master/pygments/lexers/smithy.py#L61).