Skip to content

Commit b57b749

Browse files
andriy-sudoclaude
andcommitted
fix(security): risk-accept pygments ReDoS GHSA-5239-wwwm-4pmq (ENG-13216)
- pygments 2.19.2 → risk-accepted (GHSA-5239-wwwm-4pmq, CVSS 3.3 LOW) No fix available — 2.19.2 is latest and marked last_affected. ignoreUntil: 2026-06-23 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent f096b5d commit b57b749

1 file changed

Lines changed: 4 additions & 0 deletions

File tree

osv-scanner.toml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
[[IgnoredVulns]]
2+
id = "GHSA-5239-wwwm-4pmq"
3+
ignoreUntil = 2026-06-23
4+
reason = "LOW severity (CVSS 3.3). pygments 2.19.2 is the latest release and is marked last_affected — no fix version published yet. ReDoS via GUID regex only exploitable with attacker-controlled syntax highlighting inputs."

0 commit comments

Comments
 (0)