Записи pydantic
9 опубликованных записей вендора pydantic.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 88,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
- CWE-863 Incorrect Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2026-25580Эксплойта нет | Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handlingpydantic · pydantic ai · CWE-918 | Высокая8,6 | — | 0,7 % | 6 февр. 2026 г. |
30Наблюдать | CVE-2021-29510Эксплойта нет | Use of "infinity" as an input to datetime and date fields causes infinite loop in pydanticpydantic · pydantic · CWE-835 | Высокая7,5 | — | 1,0 % | 13 мая 2021 г. |
30Наблюдать | CVE-2024-3772Эксплойта нет | Regular expression denial of service in Pydantic < 2.4.0pydantic · pydantic · CWE-1333 | Высокая7,5 | — | 1,0 % | 14 апр. 2024 г. |
27Наблюдать | CVE-2026-48782Эксплойта нет | pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)pydantic · pydantic ai · CWE-918 | Средняя6,8 | — | 0,4 % | 17 июн. 2026 г. |
27Наблюдать | CVE-2026-54249Эксплойта нет | VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via provider metadata injectionpydantic · pydantic ai · CWE-918 | Средняя6,8 | — | 0,3 % | 29 июл. 2026 г. |
26Наблюдать | CVE-2026-65975Эксплойта нет | Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute when a trailing message is dropped during `sanitize_messages`pydantic · pydantic ai · CWE-863 | Средняя6,5 | — | 0,3 % | 29 июл. 2026 г. |
23Наблюдать | CVE-2026-46678Эксплойта нет | Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)pydantic · pydantic ai · CWE-918 | Средняя5,9 | — | 0,4 % | 29 июл. 2026 г. |
21Наблюдать | CVE-2026-25640Эксплойта нет | Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URLpydantic · pydantic ai · CWE-22 | Средняя5,4 | — | 0,4 % | 6 февр. 2026 г. |
21Наблюдать | CVE-2026-58203Эксплойта нет | NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_sizepydantic · pydantic-settings · CWE-22 | Средняя5,3 | — | 0,2 % | 6 июл. 2026 г. |
- CVE-2026-2558034Наблюдать
Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handling
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %pydantic · pydantic ai6 февр. 2026 г.
- CVE-2021-2951030Наблюдать
Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pydantic · pydantic13 мая 2021 г.
- CVE-2024-377230Наблюдать
Regular expression denial of service in Pydantic < 2.4.0
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %pydantic · pydantic14 апр. 2024 г.
- CVE-2026-4878227Наблюдать
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
СредняяCVSS 6,8Эксплойта нетEPSS 0 %pydantic · pydantic ai17 июн. 2026 г.
- CVE-2026-5424927Наблюдать
VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via provider metadata injection
СредняяCVSS 6,8Эксплойта нетEPSS 0 %pydantic · pydantic ai29 июл. 2026 г.
- CVE-2026-6597526Наблюдать
Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute when a trailing message is dropped during `sanitize_messages`
СредняяCVSS 6,5Эксплойта нетEPSS 0 %pydantic · pydantic ai29 июл. 2026 г.
- CVE-2026-4667823Наблюдать
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
СредняяCVSS 5,9Эксплойта нетEPSS 0 %pydantic · pydantic ai29 июл. 2026 г.
- CVE-2026-2564021Наблюдать
Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URL
СредняяCVSS 5,4Эксплойта нетEPSS 0 %pydantic · pydantic ai6 февр. 2026 г.
- CVE-2026-5820321Наблюдать
NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
СредняяCVSS 5,3Эксплойта нетEPSS 0 %pydantic · pydantic-settings6 июл. 2026 г.