Vulnerabilidades em Pydantic
8 resultadosAnálise Vexday
Pydantic apresenta footprint de risco mínimo com apenas 1 CVE registrada na base, nenhuma sob ataque ativo ou com classificação crítica. A vulnerabilidade não é recente e envolve CWE-1333 (Improper Restriction of Rendered UI Layers or Frames), representando exposição baixa no contexto atual.
CVE-2024-3772MEDIUMRegular expression denial of service in Pydantic < 2.4.0EPSS 1.0%CVE-2026-25580HIGHPydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download HandlingEPSS 0.6%CVE-2026-46678MEDIUMPydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)EPSS 0.4%CVE-2026-25640HIGHPydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URLEPSS 0.3%CVE-2026-48782MEDIUMpydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)EPSS 0.3%CVE-2026-65975MEDIUMPydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute when a trailing message is dropped during `sanitize_messages`EPSS 0.2%CVE-2026-54249MEDIUMVercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via provider metadata injectionEPSS 0.2%CVE-2026-58203MEDIUMNestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_sizeEPSS 0.2%