CVE-2021-27291

In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 89.55%
Affected Products (NVD)
VendorProductVersion
pygmentspygments
1.1 ≤
𝑥
< 2.7.4
debiandebian_linux
9.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
mediawiki
bookworm
1:1.39.7-1~deb12u1
fixed
bookworm (security)
1:1.39.10-1~deb12u1
fixed
bullseye
1:1.35.13-1+deb11u2
fixed
bullseye (security)
1:1.35.13-1+deb11u3
fixed
sid
1:1.39.10-1
fixed
trixie
1:1.39.10-1
fixed
pygments
bookworm
2.14.0+dfsg-1
fixed
bullseye
2.7.1+dfsg-2.1
fixed
sid
2.18.0+dfsg-1
fixed
trixie
2.18.0+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
eric
bionic
needs-triage
focal
needs-triage
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needed
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needed
oracular
ignored
plucky
ignored
questing
ignored
resolute
needed
trusty
dne
xenial
ignored
pygments
bionic
Fixed 2.2.0+dfsg-1ubuntu0.2
released
focal
Fixed 2.3.1+dfsg-1ubuntu2.2
released
groovy
Fixed 2.3.1+dfsg-4ubuntu0.2
released
hirsute
Fixed 2.7.1+dfsg-2ubuntu1
released
impish
Fixed 2.7.1+dfsg-2ubuntu1
released
jammy
Fixed 2.7.1+dfsg-2ubuntu1
released
kinetic
Fixed 2.7.1+dfsg-2ubuntu1
released
lunar
Fixed 2.7.1+dfsg-2ubuntu1
released
mantic
Fixed 2.7.1+dfsg-2ubuntu1
released
noble
Fixed 2.7.1+dfsg-2ubuntu1
released
oracular
Fixed 2.7.1+dfsg-2ubuntu1
released
plucky
Fixed 2.7.1+dfsg-2ubuntu1
released
questing
Fixed 2.7.1+dfsg-2ubuntu1
released
resolute
Fixed 2.7.1+dfsg-2ubuntu1
released
trusty
Fixed 1.6+dfsg-1ubuntu1.1+esm1
released
xenial
Fixed 2.1+dfsg-1ubuntu0.2
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
resource-agents
RHEL 8
0:4.1.1-98.el8
fixed
resource-agents-aliyun
RHEL 8
0:4.1.1-98.el8
fixed
resource-agents-gcp
RHEL 8
0:4.1.1-98.el8
fixed
resource-agents-paf
RHEL 8
0:4.1.1-98.el8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python-pygments
Amazon Linux 2
0:1.4-10.amzn2.0.1
fixed
python3-pygments
Amazon Linux 2
0:2.2.0-3.amzn2.0.3
fixed
python3-pygments-doc
Amazon Linux 2
0:2.2.0-3.amzn2.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
python-pygments
Azure Linux 3.0
0:2.7.4-1.azl3
fixed
CBL-Mariner 1.0
0:2.4.2-6.cm1
fixed
CBL-Mariner 2.0
0:2.4.2-7.cm2
fixed