One of the pip-audit version 2.10.0 dependencies seem to introduce a security vulnerability.
https://nvd.nist.gov/vuln/detail/CVE-2026-4539
GHSA-5239-wwwm-4pmq
$ pipdeptree --reverse --package pygments
Pygments==2.19.2
└── rich==14.3.3 [requires: Pygments>=2.13.0,<3.0.0]
└── pip_audit==2.10.0 [requires: rich>=12.4
$ pip list
Package Version
----------------------- ---------
boolean.py 5.0
CacheControl 0.14.4
certifi 2026.2.25
charset-normalizer 3.4.6
cyclonedx-python-lib 11.7.0
defusedxml 0.7.1
filelock 3.25.2
idna 3.11
license-expression 30.4.4
markdown-it-py 4.0.0
mdurl 0.1.2
msgpack 1.1.2
packageurl-python 0.17.6
packaging 26.0
pip 26.0.1
pip-api 0.0.34
pip_audit 2.10.0
pip-requirements-parser 32.0.1
platformdirs 4.9.4
py-serializable 2.1.0
Pygments 2.19.2
pyparsing 3.3.2
requests 2.32.5
rich 14.3.3
sortedcontainers 2.4.0
tomli 2.4.0
tomli_w 1.2.0
typing_extensions 4.15.0
urllib3 2.6.3
One of the
pip-auditversion 2.10.0 dependencies seem to introduce a security vulnerability.https://nvd.nist.gov/vuln/detail/CVE-2026-4539
GHSA-5239-wwwm-4pmq