PatchSiren

pydantic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM pydantic CVE published 2026-07-06

CVE-2026-58203

The CVE record describes a local file read vulnerability in pydantic-settings versions from 2.12.0 to 2.14.2. An attacker with influence over the configured secrets directory can read files outside the directory, bypassing the documented size protection. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of pydantic-settings, especially those with shared or writable sec [truncated]

MEDIUM pydantic CVE published 2026-06-17

CVE-2026-48782

CVE-2026-48782 is a medium-severity vulnerability in Pydantic AI, a Python agent framework for building applications and workflows with Generative AI. The issue affects versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2. An attacker can bypass the cloud-metadata blocklist by encoding metadata IP in an IPv6 transition form, exposing cloud IAM short-term credentials. This occurs when an application using [truncated]

HIGH pydantic CVE published 2026-02-06

CVE-2026-25580

CVE-2026-25580 is a high-severity Server-Side Request Forgery (SSRF) vulnerability in Pydantic AI, a Python agent framework. The vulnerability allows attackers to make HTTP requests to internal network resources by including malicious URLs in message history from untrusted sources. This could potentially lead to access to internal services or cloud credentials. The vulnerability affects applications that [truncated]