Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early | High Risk 7.5 | 5 hours ago | 4 hours ago |
|
|
Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early | High Risk 7.5 | 5 hours ago | 4 hours ago |
|
|
Pydantic AI: Excessive resource use when local web fetching converts nested HTML | Medium Risk 6.5 | 7 hours ago | 6 hours ago |
|
|
Pydantic AI: Excessive resource use when local web fetching converts nested HTML | Medium Risk 6.5 | 7 hours ago | 6 hours ago |
|
|
Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpoint | High Risk 7.6 | 7 hours ago | 7 hours ago |
|
|
Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpoint | High Risk 7.6 | 7 hours ago | 7 hours ago |
|
|
Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False` | Low Risk 3.0 | 7 hours ago | 7 hours ago |
|
|
Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False` | Low Risk 3.0 | 7 hours ago | 7 hours ago |
|
|
Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header | Medium Risk 6.4 | 7 hours ago | 7 hours ago |
|
|
Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header | Medium Risk 6.4 | 7 hours ago | 7 hours ago |
|
|
Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl | Medium Risk 6.5 | 7 hours ago | 7 hours ago |
|
|
Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl | Medium Risk 6.5 | 7 hours ago | 7 hours ago |
|
|
Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False` | Low Risk 3.0 | 8 hours ago | 7 hours ago |
|
|
Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False` | Low Risk 3.0 | 8 hours ago | 7 hours ago |
|
|
Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch` | Medium Risk 6.5 | 8 hours ago | 7 hours ago |
|
|
Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch` | Medium Risk 6.5 | 8 hours ago | 7 hours ago |
|
|
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers | Medium Risk 6.8 | 8 hours ago | 7 hours ago |
|
|
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers | Medium Risk 6.8 | 8 hours ago | 7 hours ago |
|
|
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials | Medium Risk 6.8 | 1 month ago | 1 month ago |
|
|
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials | Medium Risk 6.8 | 1 month ago | 1 month ago |
|
|
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials | Medium Risk 6.8 | 1 month ago | 1 month ago |
|
|
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials | Medium Risk 6.8 | 1 month ago | 1 month ago |
|
|
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL | High Risk 7.1 | 8 months ago | 2 months ago |
|
|
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL | High Risk 7.1 | 8 months ago | 2 months ago |
|
|
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL | High Risk 7.1 | 2 months ago | 2 months ago |
|
|
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL | High Risk 7.1 | 2 months ago | 2 months ago |
|
|
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678) | Medium Risk 6.8 | 3 months ago | 2 months ago |
|
|
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678) | Medium Risk 6.8 | 3 months ago | 2 months ago |
|
|
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678) | Medium Risk 6.8 | 2 months ago | 2 months ago |
|
|
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678) | Medium Risk 6.8 | 2 months ago | 2 months ago |
|
|
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) | Medium Risk 6.8 | 4 months ago | 2 months ago |
|
|
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) | Medium Risk 6.8 | 4 months ago | 2 months ago |
|
|
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) | Medium Risk 6.8 | 2 months ago | 2 months ago |
|
|
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) | Medium Risk 6.8 | 2 months ago | 2 months ago |
|
|
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling | High Risk 8.6 | 8 months ago | 2 months ago |
|
|
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling | High Risk 8.6 | 8 months ago | 2 months ago |
|
|
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling | High Risk 8.6 | 2 months ago | 2 months ago |
|
|
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling | High Risk 8.6 | 2 months ago | 2 months ago |
Page 1