Collerek maintains a focused open-source ORM library, Ormar, designed for building database-driven Python applications with asynchronous support. The vulnerability signal centers on input-handling and query-construction weaknesses, including improper input validation and SQL injection, which are characteristic risks in object-relational mapping layers where user-supplied data flows into database operations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Collerek over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27953CRITICAL ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing any unauthenticated user to ski | Mar 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-26198HIGH Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by passing user-supplied column name | Feb 24, 2026 | 7.5 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Collerek.
Media articles that mention a CVE ID that affects a product developed by Collerek — matched by CVE ID, not by vendor name.