Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Pydantic — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting Pydantic. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Pydantic serves as a data validation library using Python type annotations to enforce data structures, primarily used in API development and configuration management. Historically, vulnerabilities have included remote code execution through unsafe deserialization and cross-site scripting from improper input sanitization. The library has faced security issues related to privilege escalation in versions prior to 1.9 due to path traversal flaws. While maintaining three CVEs, Pydantic's security posture has improved with stricter validation defaults and regular security audits, making it a generally secure choice when properly configured and updated.

Found 16 results / 23 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-107295 `pydantic-ai-slim` web UI `/api/chat` accepts browser-simple cross-origin requests that can trigger agent tool execution — pydantic-ai CWE-352 7.6 High 2026-10-08
CVE-2026-107294 Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl — pydantic-ai CWE-400 6.5 Medium 2026-10-08
CVE-2026-107293 Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False` — pydantic-ai CWE-212 2.3 Low 2026-10-08
CVE-2026-107292 Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header — pydantic-ai CWE-346 6.4 Medium 2026-10-08
CVE-2026-107291 Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False` — pydantic-ai CWE-212 2.3 Low 2026-10-08
CVE-2026-107290 Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch` — pydantic-ai CWE-1333 6.5 Medium 2026-10-08
CVE-2026-107289 Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifier (incomplete fix for CVE-2026-46678 and CVE-2026-48782) — pydantic-ai CWE-918 6.8 Medium 2026-10-08
CVE-2026-107288 Pydantic AI: web_fetch_tool blocked_domains bypass via a hostname the resolver normalizes differently — pydantic-ai CWE-918 3.7 Low 2026-10-08
CVE-2026-107287 Pydantic AI: Excessive resource use when local web fetching converts nested HTML — pydantic-ai CWE-400 6.5 Medium 2026-10-08
CVE-2026-107286 Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early — pydantic-ai CWE-772 7.5 High 2026-10-08
CVE-2026-54249 VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via provider metadata injection — pydantic-ai CWE-918 6.8 Medium 2026-07-29
CVE-2026-46678 Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) — pydantic-ai CWE-918 6.8 Medium 2026-07-29
CVE-2026-65975 Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute when a trailing message is dropped during `sanitize_messages` — pydantic-ai CWE-863 6.5 Medium 2026-07-29
CVE-2026-48782 pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678) — pydantic-ai CWE-918 6.8 Medium 2026-06-16
CVE-2026-25580 Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handling — pydantic-ai CWE-918 8.6 High 2026-02-06
CVE-2026-25640 Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URL — pydantic-ai CWE-22 7.1 High 2026-02-06

This page lists every published CVE security advisory associated with Pydantic. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.