CVE-2026-27953 is a critical Pydantic validation bypass vulnerability affecting collerek ormar versions 0.23.0 and below, an async mini ORM for Python, which has been patched in version 0.23.1. This flaw allows unauthenticated attackers to skip all field validation or selectively nullify arbitrary model fields by injecting specific parameters into JSON request bodies, primarily impacting FastAPI integrations. Rated with a CVSS score of 9.8 (CRITICAL), it is easily exploitable over the network without authentication or user interaction, enabling privilege escalation, data integrity violations, and business logic bypass. While no active exploitation or public exploit code has been identified, and community discussion is minimal, its severe potential impact warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.23.1CPE matchmatch criteria | cpe:2.3:a:collerek:ormar:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.