CVE-2021-20270
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
02 / AFFECTED SOFTWARE
Affected packages
25 explicit affected versions
25 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
05 / REFERENCES
Further evidence
- https://bugzilla.redhat.com/show_bug.cgi?id=1922136
- https://github.com/pygments/pygments
- https://github.com/pygments/pygments/commit/f91804ff4772e3ab41f46e28d370f57898700333
- https://github.com/pypa/advisory-database/tree/main/vulns/pygments/PYSEC-2021-140.yaml
- https://lists.debian.org/debian-lts-announce/2021/05/msg00003.html
- https://lists.debian.org/debian-lts-announce/2021/05/msg00006.html
- https://nvd.nist.gov/vuln/detail/CVE-2021-20270
- https://www.debian.org/security/2021/dsa-4889
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://github.com/advisories/GHSA-9w8r-397f-prfh