Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 304 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.33% | — | Pydantic AI | 29/7/2026 | 4/8/2026 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and 2.0.0b1 up to but not including 2.5.0, the UI adapters (AG-UI via Agent.to_ag_ui()/AGUIAdapter, and Vercel AI via VercelAIAdapter) use sanitize_messages to strip… | |
| Analizada | Media (6.8) | 0.32% | — | Pydantic AI | 29/7/2026 | 4/8/2026 | Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application's model-provider or… | |
| Analizada | Media (5.9) | 0.38% | — | Pydantic AI | 29/7/2026 | 4/8/2026 | Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local' (disabling the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an… | |
| Analizada | Media (5.3) | 0.18% | — | Pydantic-settings | 6/7/2026 | 27/7/2026 | pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files in a configured secrets_dir. When secrets_nested_subdir=True, a directory entry inside secrets_dir that is a symbolic link pointing outside secrets_dir is followed, so… | |
| Analizada | Media (6.8) | 0.42% | — | Pydantic AI | 17/6/2026 | 6/8/2026 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form that the previous fix, CVE-2026-46678, did not decode,… | |
| Aplazada | Media (5.8) | 0.20% | — | Pydantic-aiAIPydantic Mcp-run-pythonAIDenoAI | 9/2/2026 | 17/6/2026 | The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to access the localhost interface of the host to perform SSRF attacks. Note - the "mcp-run-python" project is archived and unlikely to receive a fix. | |
| Modificada | Alta (8.6) | 0.67% | — | Pydantic AI | 6/2/2026 | 15/7/2026 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When applications accept message history from untrusted sources, attackers can include… | |
| Modificada | Media (5.4) | 0.41% | — | Pydantic AI | 6/2/2026 | 15/7/2026 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI web UI allows an attacker to serve arbitrary JavaScript in the context of the application by crafting a malicious URL. In affected… | |
| Aplazada | Baja (3.7) | 0.38% | — | DjangoAISqlalchemyAIPydanticAIStrawberry GraphqlAI | 9/1/2025 | 17/6/2026 | Strawberry GraphQL is a library for creating GraphQL APIs. Starting in 0.182.0 and prior to version 0.257.0, a type confusion vulnerability exists in Strawberry GraphQL's relay integration that affects multiple ORM integrations (Django, SQLAlchemy, Pydantic). The vulnerability occurs when multiple GraphQL types are… | |
| Analizada | Alta (7.5) | 0.96% | — | PydanticFedoraproject Fedora | 15/4/2024 | 17/6/2026 | Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string. | |
| Modificada | Alta (7.5) | 0.97% | — | PydanticFedoraproject Fedora | 13/5/2021 | 17/6/2026 | Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU). Pydantic has been patched with fixes… |