Dynaconf is a configuration management library for Python applications that handles dynamic settings and environment variable injection, presenting a narrow but focused attack surface centered on code execution risks. The recurring vulnerability classes—code injection, template-engine neutralization failures, and OS command injection—reflect the inherent hazards of processing untrusted configuration input and dynamic code generation, which defenders should monitor closely in applications that expose configuration endpoints or accept external configuration sources. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dynaconf over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33154HIGH dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation i | Mar 20, 2026 | 8.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dynaconf.
Media articles that mention a CVE ID that affects a product developed by Dynaconf — matched by CVE ID, not by vendor name.