CVE-2026-4539: ReDoS vulnerability in pygments #7

Closed
opened 2026-03-25 09:05:00 -04:00 by LogalDeveloper · 0 comments
Owner

pip-audit flagged CVE-2026-4539 in pygments.

pygments is not a direct dependency of Owncast Sentry. It is pulled in transitively by hatch and, ironically, pip-audit, both of which are dev dependencies. It is not present in the production runtime environment and is never invoked by Owncast Sentry itself, so this vulnerability has no impact on deployed instances.

The upstream issue has been reported at pygments/pygments#3058 but has not yet been addressed. There is no fixed version available at this time.

`pip-audit` flagged CVE-2026-4539 in `pygments`. `pygments` is not a direct dependency of Owncast Sentry. It is pulled in transitively by `hatch` and, ironically, `pip-audit`, both of which are dev dependencies. It is not present in the production runtime environment and is never invoked by Owncast Sentry itself, so this vulnerability has no impact on deployed instances. The upstream issue has been reported at [pygments/pygments#3058](https://github.com/pygments/pygments/issues/3058) but has not yet been addressed. There is no fixed version available at this time.
LogalDeveloper added the Bug label 2026-03-25 09:05:00 -04:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: LogalDeveloper/OwncastSentry#7