Update dependency pygments to v2.20.0 [SECURITY] #98

Open
renovate[bot] wants to merge 1 commit from renovate/pypi-pygments-vulnerability into main
renovate[bot] commented 2026-06-11 18:58:46 +00:00 (Migrated from github.com)

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
pygments (changelog) ==2.19.1 → ==2.20.0 age adoption passing confidence

Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching

CVE-2026-4539 / GHSA-5239-wwwm-4pmq

More information

Details

A security flaw has been discovered in pygments before 2.20.0. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Severity

  • CVSS Score: 1.9 / 10 (Low)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

pygments/pygments (pygments)

v2.20.0

Compare Source

(released March 29th, 2026)

v2.19.2

Compare Source

(released June 21st, 2025)


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Adoption](https://docs.renovatebot.com/merge-confidence/) | [Passing](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [pygments](https://redirect.github.com/pygments/pygments) ([changelog](https://redirect.github.com/pygments/pygments/blob/master/CHANGES)) | `==2.19.1` → `==2.20.0` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/pygments/2.20.0?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/pypi/pygments/2.20.0?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/pypi/pygments/2.19.1/2.20.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/pygments/2.19.1/2.20.0?slim=true) | --- ### Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching [CVE-2026-4539](https://nvd.nist.gov/vuln/detail/CVE-2026-4539) / [GHSA-5239-wwwm-4pmq](https://redirect.github.com/advisories/GHSA-5239-wwwm-4pmq) <details> <summary>More information</summary> #### Details A security flaw has been discovered in pygments before 2.20.0. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. #### Severity - CVSS Score: 1.9 / 10 (Low) - Vector String: `CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P` #### References - [https://nvd.nist.gov/vuln/detail/CVE-2026-4539](https://nvd.nist.gov/vuln/detail/CVE-2026-4539) - [https://github.com/pygments/pygments/issues/3058](https://redirect.github.com/pygments/pygments/issues/3058) - [https://github.com/pygments/pygments](https://redirect.github.com/pygments/pygments) - [https://vuldb.com/?ctiid.352327](https://vuldb.com/?ctiid.352327) - [https://vuldb.com/?id.352327](https://vuldb.com/?id.352327) - [https://vuldb.com/?submit.774685](https://vuldb.com/?submit.774685) - [https://github.com/pygments/pygments/pull/3064](https://redirect.github.com/pygments/pygments/pull/3064) - [https://github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc](https://redirect.github.com/pygments/pygments/commit/24b8aa76c6cd6d70f39c6dd605cce319c98e2ccc) - [https://github.com/pygments/pygments/releases/tag/2.20.0](https://redirect.github.com/pygments/pygments/releases/tag/2.20.0) - [https://github.com/advisories/GHSA-5239-wwwm-4pmq](https://redirect.github.com/advisories/GHSA-5239-wwwm-4pmq) This data is provided by the [GitHub Advisory Database](https://redirect.github.com/advisories/GHSA-5239-wwwm-4pmq) ([CC-BY 4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>pygments/pygments (pygments)</summary> ### [`v2.20.0`](https://redirect.github.com/pygments/pygments/blob/HEAD/CHANGES#Version-2200) [Compare Source](https://redirect.github.com/pygments/pygments/compare/2.19.2...2.20.0) (released March 29th, 2026) - New lexers: - Rell ([#&#8203;2914](https://redirect.github.com/pygments/pygments/issues/2914)) - Updated lexers: - archetype: Fix catastrophic backtracking in GUID and ID patterns ([#&#8203;3064](https://redirect.github.com/pygments/pygments/issues/3064)) - ASN.1: Recognize minus sign and fix range operator ([#&#8203;3014](https://redirect.github.com/pygments/pygments/issues/3014), [#&#8203;3060](https://redirect.github.com/pygments/pygments/issues/3060)) - C++: Add C++26 keywords ([#&#8203;2955](https://redirect.github.com/pygments/pygments/issues/2955)), add integer literal suffixes ([#&#8203;2966](https://redirect.github.com/pygments/pygments/issues/2966)) - ComponentPascal: Fix `analyse_text` ([#&#8203;3028](https://redirect.github.com/pygments/pygments/issues/3028), [#&#8203;3032](https://redirect.github.com/pygments/pygments/issues/3032)) - Coq renamed to Rocq ([#&#8203;2883](https://redirect.github.com/pygments/pygments/issues/2883), [#&#8203;2908](https://redirect.github.com/pygments/pygments/issues/2908)) - Cython: Various improvements ([#&#8203;2932](https://redirect.github.com/pygments/pygments/issues/2932), [#&#8203;2933](https://redirect.github.com/pygments/pygments/issues/2933)) - Debian control: Improve architecture parsing ([#&#8203;3052](https://redirect.github.com/pygments/pygments/issues/3052)) - Devicetree: Add support for overlay/fragments ([#&#8203;3021](https://redirect.github.com/pygments/pygments/issues/3021)), add bytestring support ([#&#8203;3022](https://redirect.github.com/pygments/pygments/issues/3022)), fix catastrophic backtracking ([#&#8203;3057](https://redirect.github.com/pygments/pygments/issues/3057)) - Fennel: Various improvements ([#&#8203;2911](https://redirect.github.com/pygments/pygments/issues/2911)) - Haskell: Handle escape sequences in character literals ([#&#8203;3069](https://redirect.github.com/pygments/pygments/issues/3069), [#&#8203;1795](https://redirect.github.com/pygments/pygments/issues/1795)) - Java: Add module keywords ([#&#8203;2955](https://redirect.github.com/pygments/pygments/issues/2955)) - Lean4: Add operators `]'`, `]?`, `]!` ([#&#8203;2946](https://redirect.github.com/pygments/pygments/issues/2946)) - LESS: Support single-line comments ([#&#8203;3005](https://redirect.github.com/pygments/pygments/issues/3005)) - LilyPond: Update to 2.25.29 ([#&#8203;2974](https://redirect.github.com/pygments/pygments/issues/2974)) - LLVM: Support C-style comments ([#&#8203;3023](https://redirect.github.com/pygments/pygments/issues/3023), [#&#8203;2978](https://redirect.github.com/pygments/pygments/issues/2978)) - Lua(u): Fix catastrophic backtracking ([#&#8203;3047](https://redirect.github.com/pygments/pygments/issues/3047)) - Macaulay2: Update to 1.25.05 ([#&#8203;2893](https://redirect.github.com/pygments/pygments/issues/2893)), 1.25.11 ([#&#8203;2988](https://redirect.github.com/pygments/pygments/issues/2988)) - Mathematica: Various improvements ([#&#8203;2957](https://redirect.github.com/pygments/pygments/issues/2957)) - meson: Add additional operators ([#&#8203;2919](https://redirect.github.com/pygments/pygments/issues/2919)) - MySQL: Update keywords ([#&#8203;2970](https://redirect.github.com/pygments/pygments/issues/2970)) - org-Mode: Support both schedule and deadline ([#&#8203;2899](https://redirect.github.com/pygments/pygments/issues/2899)) - PHP: Add `__PROPERTY__` magic constant ([#&#8203;2924](https://redirect.github.com/pygments/pygments/issues/2924)), add reserved keywords ([#&#8203;3002](https://redirect.github.com/pygments/pygments/issues/3002)) - PostgreSQL: Add more keywords ([#&#8203;2985](https://redirect.github.com/pygments/pygments/issues/2985)) - protobuf: Fix namespace tokenization ([#&#8203;2929](https://redirect.github.com/pygments/pygments/issues/2929)) - Python: Add `t`-string support ([#&#8203;2973](https://redirect.github.com/pygments/pygments/issues/2973), [#&#8203;3009](https://redirect.github.com/pygments/pygments/issues/3009), [#&#8203;3010](https://redirect.github.com/pygments/pygments/issues/3010)) - Tablegen: Fix infinite loop ([#&#8203;2972](https://redirect.github.com/pygments/pygments/issues/2972), [#&#8203;2940](https://redirect.github.com/pygments/pygments/issues/2940)) - Tera Term macro: Add commands introduced in v5.3 through v5.6 ([#&#8203;2951](https://redirect.github.com/pygments/pygments/issues/2951)) - TOML: Support TOML 1.1.0 ([#&#8203;3026](https://redirect.github.com/pygments/pygments/issues/3026), [#&#8203;3027](https://redirect.github.com/pygments/pygments/issues/3027)) - Turtle: Allow empty comment lines ([#&#8203;2980](https://redirect.github.com/pygments/pygments/issues/2980)) - XML: Added `.xbrl` as file ending ([#&#8203;2890](https://redirect.github.com/pygments/pygments/issues/2890), [#&#8203;2891](https://redirect.github.com/pygments/pygments/issues/2891)) - Drop Python 3.8, and add Python 3.14 as a supported version ([#&#8203;2987](https://redirect.github.com/pygments/pygments/issues/2987), [#&#8203;3012](https://redirect.github.com/pygments/pygments/issues/3012)) - Various improvements to `autopygmentize` ([#&#8203;2894](https://redirect.github.com/pygments/pygments/issues/2894)) - Update `onedark` style to support more token types ([#&#8203;2977](https://redirect.github.com/pygments/pygments/issues/2977)) - Update `rtt` style to support more token types ([#&#8203;2895](https://redirect.github.com/pygments/pygments/issues/2895)) - Cache entry points to improve performance ([#&#8203;2979](https://redirect.github.com/pygments/pygments/issues/2979)) - Fix `xterm-256` color table ([#&#8203;3043](https://redirect.github.com/pygments/pygments/issues/3043)) - Fix `kwargs` dictionary getting mutated on each call ([#&#8203;3044](https://redirect.github.com/pygments/pygments/issues/3044)) ### [`v2.19.2`](https://redirect.github.com/pygments/pygments/blob/HEAD/CHANGES#Version-2192) [Compare Source](https://redirect.github.com/pygments/pygments/compare/2.19.1...2.19.2) (released June 21st, 2025) - Lua: Fix regression introduced in 2.19.0 ([#&#8203;2882](https://redirect.github.com/pygments/pygments/issues/2882), [#&#8203;2839](https://redirect.github.com/pygments/pygments/issues/2839)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/sarumaj/rag-agent). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTkuMCIsInVwZGF0ZWRJblZlciI6IjQ0LjU3LjMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/pypi-pygments-vulnerability:renovate/pypi-pygments-vulnerability
git switch renovate/pypi-pygments-vulnerability

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/pypi-pygments-vulnerability
git switch renovate/pypi-pygments-vulnerability
git rebase main
git switch main
git merge --ff-only renovate/pypi-pygments-vulnerability
git switch renovate/pypi-pygments-vulnerability
git rebase main
git switch main
git merge --no-ff renovate/pypi-pygments-vulnerability
git switch main
git merge --squash renovate/pypi-pygments-vulnerability
git switch main
git merge --ff-only renovate/pypi-pygments-vulnerability
git switch main
git merge renovate/pypi-pygments-vulnerability
git push origin main
Sign in to join this conversation.
No description provided.