Vulnerabilities > Pygments > Pygments > 1.2.2

DATE CVE VULNERABILITY TITLE RISK
2023-07-19 CVE-2022-40896 Unrestricted Upload of File with Dangerous Type vulnerability in Pygments
A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
local
low complexity
pygments CWE-434
5.5
2021-03-17 CVE-2021-27291 In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions.
network
low complexity
pygments debian fedoraproject
7.5
2016-01-08 CVE-2015-8557 OS Command Injection vulnerability in multiple products
The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
network
canonical pygments CWE-78
critical
9.3