Root has patched CVE-2022-40896 in the rootio-Pygments package for Root:PyPI. Multiple fixed versions available.
{ "distro": "pypi", "source": "Root", "distro_version": "" }
1.0
"https://api.root.io/external/osv/ROOT-APP-PYPI-CVE-2022-40896.json"
"root.io.1"
[ "2.12.0+root.io.1" ]
true
"2.12.0"