CVE-2026-4539 | pygments up to 2.19.2 archetype.py AdlLexer redos (Issue 3058 / EUVD-2026-14287)
A vulnerability, which was classified as problematic, was found in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity.
This vulnerability is identified as CVE-2026-4539. The attack is only possible with local access. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.