---
schema_version: '1.0'
id: security-20260714-b013cc
url: https://osv.dev/vulnerability/PYSEC-2026-2987
url_hash: b013cc2ddd6c65cf19ccd82a9960a8ac16bbec96450f18d7d579b63c98d6d3f0
canonical_url: https://osv.dev/vulnerability/PYSEC-2026-2987
source: osv:pypa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2026-4539
- PYSEC-2026-2987
- severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- pygments
- PyPI
lang: en
published_at: '2026-07-13T14:36:44Z'
fetched_at: '2026-07-14T06:42:23Z'
updated_at: '2026-07-14T06:44:25Z'
status: published
content_hash: f6bdcd751b74f993e31172e4ba7da3c4857346fcecb6e58f57334da37a459d04
license_note: full
summary: Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient
  Regex for GUID Matching
summary_source: rss
summary_en: Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient
  Regex for GUID Matching
entities:
- name: HashMark
  type: other
- name: heart expression
  type: emotionalsymbol
key_facts: []
related: []
related_auto:
- name: 井案
  type: UNKNOWN
  weight: 1.0
title: 'CVE-2026-4539: Pygments has Regular Expression Denial of Service (ReDoS) due
  to Inefficient Regex for GUID Matching'
---

# CVE-2026-4539: Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

## TL;DR
Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

## Key Points
- cve / CVE-2026-4539 / PYSEC-2026-2987 / severity:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L / pygments / PyPI

## Details
**Severity:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
**Advisory:** PYSEC-2026-2987 (CVE-2026-4539)

**Affected (your watchlist):**
- `PyPI:pygments` 2.19.2 → fixed in 2.20.0 [docker/docker-llmwiki+docker/docker-strands]

**Details:**
A security flaw has been discovered in pygments before 2.20.0. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

**References:**
- https://nvd.nist.gov/vuln/detail/CVE-2026-4539
- https://github.com/pygments/pygments/issues/3058
- https://github.com/pygments/pygments/pull/3064
- https://github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc
- https://github.com/pygments/pygments
- https://github.com/pygments/pygments/releases/tag/2.20.0
- https://vuldb.com/?ctiid.352327
- https://vuldb.com/?id.352327
- https://vuldb.com/?submit.774685
- https://pypi.org/project/pygments

_Data: OSV.dev (upstream: pypa) — https://osv.dev/vulnerability/PYSEC-2026-2987_

## Source
元記事: [CVE-2026-4539: Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching](https://osv.dev/vulnerability/PYSEC-2026-2987) — published 2026-07-13T14:36:44Z
