CVE-2026-4539General

LOWCVSS 1.9 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-03-22); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-03-22: 4Mentions · 2026-04-02: 1Mentions · 2026-05-01: 1Mentions · 2026-06-12: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-06-12: 1Technical Details · 2026-03-22: 3Technical Details · 2026-05-01: 1Technical Details · 2026-06-12: 103-2204-0205-0106-12
Signal classification3 categories
General
342.9%
Patch
342.9%
Disclosure
114.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-224
Disclosure1General3
2026-04-021
Patch1
2026-05-011
Patch1
2026-06-121
Patch1
Full discourse7 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    CVE-2026-4539: vulnerabilidade de negação de serviço no Pygments. Guia completo para o #SUSE Linux com comandos de verificação, automação do patch e mitigações com timeout/AppArmor. Saiba mais: -> http://tinyurl.com/4nhc5h4m https://t.co/alDXZKW0jM

    Post summary

    This tweet announces a denial-of-service vulnerability in Pygments and provides a guide with patch automation and mitigations, without mentioning PoC or active exploitation.

    1001055
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    New guide: Understand & fix ReDoS in Pygments (CVE-2026-4539) on openSUSE. Includes verification commands, automation script, and 5 mitigation strategies when you can't patch. Read more-> https://tinyurl.com/muhbwmf5 #openSUSE https://t.co/QRpSyjcZjI

    Post summary

    The guide supplies verification commands, an automation script, and five mitigation techniques for the ReDoS vulnerability in Pygments (CVE-2026‑4539), assisting users who cannot apply a patch.

    0000059
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #openSUSE Tumbleweed advisory 10476-1: python311-Pygments updated to 2.20.0-2.1 resolving CVE-2026-4539. Read more: 👉 https://tinyurl.com/2kpdk72m https://t.co/zOEkgkGQvq

    Post summary

    The advisory announces an update to python311-Pygments that resolves CVE-2026-4539 on openSUSE Tumbleweed.

    0000069
    1.5K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4539 📊 Severity: 3.3 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4539 #CVE-2026-4539 #CVE #Low  #CyberSecurity #InfoSec https://t.co/jjDX8qGC01

    Post summary

    The tweet announces CVE-2026-4539, noting its low severity and unspecified affected products, without providing additional technical or exploit details.

    0000019
    111 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4539 A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation r… https://www.cve.org/CVERecord?id=CVE-2026-4539

    Post summary

    The post reports a new flaw in pygments’ AdlLexer up to 2.19.2, but offers no PoC, exploit, patch, or detailed technical information.

    0000062
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4539 Pygments AdlLexer Regular Expression Complexity Vulnerability in V... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4539 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE-2026-4539, a regular expression complexity issue in Pygments AdlLexer, providing only the CVE identifier and a link to a vulnerability details page.

    0000041
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4539 - pygments http://archetype.py AdlLexer redos Intel Report: https://ift.tt/BTE9RcS

    Post summary

    The alert announces CVE‑2026‑4539 as a regex denial‑of‑service flaw in pygments AdlLexer and provides a link to an intel report, but offers no PoC, exploit code, or patch details.

    0000013
    291 followersView on X

Explore more