Junglewise Threat Intelligence

CVE-2021-20270: PYSEC-2021-140 - An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standa

CVE-2021-20270 · Severity: low · CVSS 3.1 · Published 2021-03-23

Technologies: pygments (PyPI). Vendors: PyPI.

Executive brief

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

Affected products

  • PyPI pygments

Related threats