---
id: GHSA-qc22-xmq4-qg46
title: 'c2cciutils affected by CVE-2022-40896 '
summary: 'c2cciutils affected by CVE-2022-40896 '
severity: medium
vendor: c2cciutils
product: c2cciutils
ecosystem: pip
affected:
  - c2cciutils < 1.1.67
patched:
  - c2cciutils 1.1.67
published: '2026-04-01'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:51:03.683639264Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-qc22-xmq4-qg46'
references:
  - url: >-
      https://github.com/camptocamp/c2cciutils/security/advisories/GHSA-qc22-xmq4-qg46
  - url: >-
      https://github.com/camptocamp/c2cciutils/commit/9d54eab73fcf24d492b339137040400da7ef4076
  - url: 'https://github.com/advisories/GHSA-mrwq-x4v8-fh7p'
  - url: 'https://github.com/camptocamp/c2cciutils'
tags:
  - osv
  - pip
ingestedAt: '2026-09-12T03:13:01.721Z'
---

## Overview

Pinned vulnerable version of Pygment [CVE-2022-40896](https://nvd.nist.gov/vuln/detail/CVE-2022-40896)

## Affected packages

- `c2cciutils < 1.1.67`

## Remediation

Upgrade to a patched release:

- `c2cciutils 1.1.67`
