---
schema_version: '1.0'
id: security-20260711-f28f5b
url: https://osv.dev/vulnerability/GHSA-5239-wwwm-4pmq
url_hash: f28f5b78d949b010178df901cf8b7e3efd40239d867c077259f7250efff33768
canonical_url: https://osv.dev/vulnerability/GHSA-5239-wwwm-4pmq
source: osv:ghsa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-4539
- GHSA-5239-wwwm-4pmq
- severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- pygments
- PyPI
lang: en
published_at: '2026-03-22T06:30:15Z'
fetched_at: '2026-07-11T06:37:18Z'
updated_at: '2026-07-11T06:39:54Z'
status: published
content_hash: ef612d6f5647c4c24002379f39f8eca9048be9adc4bb3949719d3f0c19241d39
license_note: full
summary: Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient
  Regex for GUID Matching
summary_source: rss
summary_en: Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient
  Regex for GUID Matching
entities:
- name: HashTag
  type: concept
key_facts: []
related: []
related_auto:
- name: SustainableQuantumComputing
  type: concept
  weight: 3.0
title: 'CVE-2026-4539: Pygments has Regular Expression Denial of Service (ReDoS) due
  to Inefficient Regex for GUID Matching'
---

# CVE-2026-4539: Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

## TL;DR
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

## Key Points
- cve / CVE-2026-4539 / GHSA-5239-wwwm-4pmq / severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L / pygments / PyPI

## Details
**Severity:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
**Advisory:** GHSA-5239-wwwm-4pmq (CVE-2026-4539)

**Affected (your watchlist):**
- `PyPI:pygments` 2.19.2 → fixed in 2.20.0 [docker/docker-llmwiki+docker/docker-strands]

**Details:**
A security flaw has been discovered in pygments before 2.20.0. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

**References:**
- https://nvd.nist.gov/vuln/detail/CVE-2026-4539
- https://github.com/pygments/pygments/issues/3058
- https://github.com/pygments/pygments/pull/3064
- https://github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc
- https://github.com/pygments/pygments
- https://github.com/pygments/pygments/releases/tag/2.20.0
- https://vuldb.com/?ctiid.352327
- https://vuldb.com/?id.352327
- https://vuldb.com/?submit.774685

_Data: OSV.dev (upstream: ghsa) — https://osv.dev/vulnerability/GHSA-5239-wwwm-4pmq_

## Source
元記事: [CVE-2026-4539: Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching](https://osv.dev/vulnerability/GHSA-5239-wwwm-4pmq) — published 2026-03-22T06:30:15Z
