Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
pydantic-ai Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early High Risk 7.5 4 hours ago 4 hours ago
pydantic-ai-slim Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early High Risk 7.5 4 hours ago 4 hours ago
pydantic-ai Pydantic AI: Excessive resource use when local web fetching converts nested HTML Medium Risk 6.5 6 hours ago 6 hours ago
pydantic-ai-slim Pydantic AI: Excessive resource use when local web fetching converts nested HTML Medium Risk 6.5 6 hours ago 6 hours ago
pydantic-ai Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpoint High Risk 7.6 6 hours ago 6 hours ago
pydantic-ai-slim Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpoint High Risk 7.6 6 hours ago 6 hours ago
pydantic-ai Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False` Low Risk 3.0 6 hours ago 6 hours ago
pydantic-ai-slim Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False` Low Risk 3.0 6 hours ago 6 hours ago
pydantic-ai Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header Medium Risk 6.4 6 hours ago 6 hours ago
pydantic-ai-slim Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header Medium Risk 6.4 6 hours ago 6 hours ago
pydantic-ai Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl Medium Risk 6.5 6 hours ago 6 hours ago
pydantic-ai-slim Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl Medium Risk 6.5 6 hours ago 6 hours ago
pydantic-ai Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False` Low Risk 3.0 7 hours ago 7 hours ago
pydantic-ai-slim Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False` Low Risk 3.0 7 hours ago 7 hours ago
pydantic-ai Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch` Medium Risk 6.5 7 hours ago 7 hours ago
pydantic-ai-slim Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch` Medium Risk 6.5 7 hours ago 7 hours ago
pydantic-ai Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers Medium Risk 6.8 7 hours ago 7 hours ago
pydantic-ai-slim Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers Medium Risk 6.8 7 hours ago 7 hours ago
pydantic-ai Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials Medium Risk 6.8 1 month ago 1 month ago
pydantic-ai-slim Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials Medium Risk 6.8 1 month ago 1 month ago
pydantic-ai Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials Medium Risk 6.8 1 month ago 1 month ago
pydantic-ai-slim Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials Medium Risk 6.8 1 month ago 1 month ago
pydantic-ai Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL High Risk 7.1 8 months ago 2 months ago
pydantic-ai-slim Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL High Risk 7.1 8 months ago 2 months ago
pydantic-ai Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL High Risk 7.1 2 months ago 2 months ago
pydantic-ai-slim Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL High Risk 7.1 2 months ago 2 months ago
pydantic-ai pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678) Medium Risk 6.8 3 months ago 2 months ago
pydantic-ai-slim pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678) Medium Risk 6.8 3 months ago 2 months ago
pydantic-ai pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678) Medium Risk 6.8 2 months ago 2 months ago
pydantic-ai-slim pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678) Medium Risk 6.8 2 months ago 2 months ago
pydantic-ai Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) Medium Risk 6.8 4 months ago 2 months ago
pydantic-ai-slim Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) Medium Risk 6.8 4 months ago 2 months ago
pydantic-ai Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) Medium Risk 6.8 2 months ago 2 months ago
pydantic-ai-slim Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) Medium Risk 6.8 2 months ago 2 months ago
pydantic-ai Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling High Risk 8.6 8 months ago 2 months ago
pydantic-ai-slim Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling High Risk 8.6 8 months ago 2 months ago
pydantic-ai Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling High Risk 8.6 2 months ago 2 months ago
pydantic-ai-slim Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling High Risk 8.6 2 months ago 2 months ago