pydantic kayıtları
pydantic üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %88,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2026-25580İstismar yok | Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handlingpydantic · pydantic ai · CWE-918 | Yüksek8,6 | — | %0,7 | 6 Şub 2026 |
30İzleyin | CVE-2021-29510İstismar yok | Use of "infinity" as an input to datetime and date fields causes infinite loop in pydanticpydantic · pydantic · CWE-835 | Yüksek7,5 | — | %1,0 | 13 May 2021 |
30İzleyin | CVE-2024-3772İstismar yok | Regular expression denial of service in Pydantic < 2.4.0pydantic · pydantic · CWE-1333 | Yüksek7,5 | — | %1,0 | 14 Nis 2024 |
27İzleyin | CVE-2026-48782İstismar yok | pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)pydantic · pydantic ai · CWE-918 | Orta6,8 | — | %0,4 | 17 Haz 2026 |
27İzleyin | CVE-2026-54249İstismar yok | VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via provider metadata injectionpydantic · pydantic ai · CWE-918 | Orta6,8 | — | %0,3 | 29 Tem 2026 |
26İzleyin | CVE-2026-65975İstismar yok | Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute when a trailing message is dropped during `sanitize_messages`pydantic · pydantic ai · CWE-863 | Orta6,5 | — | %0,3 | 29 Tem 2026 |
23İzleyin | CVE-2026-46678İstismar yok | Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)pydantic · pydantic ai · CWE-918 | Orta5,9 | — | %0,4 | 29 Tem 2026 |
21İzleyin | CVE-2026-25640İstismar yok | Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URLpydantic · pydantic ai · CWE-22 | Orta5,4 | — | %0,4 | 6 Şub 2026 |
21İzleyin | CVE-2026-58203İstismar yok | NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_sizepydantic · pydantic-settings · CWE-22 | Orta5,3 | — | %0,2 | 6 Tem 2026 |
- CVE-2026-2558034İzleyin
Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handling
YüksekCVSS 8,6İstismar yokEPSS %1pydantic · pydantic ai6 Şub 2026
- CVE-2021-2951030İzleyin
Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
YüksekCVSS 7,5İstismar yokEPSS %1pydantic · pydantic13 May 2021
- CVE-2024-377230İzleyin
Regular expression denial of service in Pydantic < 2.4.0
YüksekCVSS 7,5İstismar yokEPSS %1pydantic · pydantic14 Nis 2024
- CVE-2026-4878227İzleyin
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
OrtaCVSS 6,8İstismar yokEPSS %0pydantic · pydantic ai17 Haz 2026
- CVE-2026-5424927İzleyin
VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via provider metadata injection
OrtaCVSS 6,8İstismar yokEPSS %0pydantic · pydantic ai29 Tem 2026
- CVE-2026-6597526İzleyin
Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute when a trailing message is dropped during `sanitize_messages`
OrtaCVSS 6,5İstismar yokEPSS %0pydantic · pydantic ai29 Tem 2026
- CVE-2026-4667823İzleyin
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
OrtaCVSS 5,9İstismar yokEPSS %0pydantic · pydantic ai29 Tem 2026
- CVE-2026-2564021İzleyin
Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URL
OrtaCVSS 5,4İstismar yokEPSS %0pydantic · pydantic ai6 Şub 2026
- CVE-2026-5820321İzleyin
NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
OrtaCVSS 5,3İstismar yokEPSS %0pydantic · pydantic-settings6 Tem 2026