Pydantic is a widely embedded Python data-validation library and framework used across web applications and API services, where its core role in input parsing and schema enforcement creates exposure to data-handling flaws. Observed vulnerabilities center on input-validation and processing weaknesses, including path traversal, cross-site scripting, inefficient regular-expression handling, infinite loops, and server-side request forgery, reflecting the parsing and neutralization demands of a validation-focused library at the application entry point. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pydantic over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25580HIGH Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability | Feb 6, 2026 | 8.6 | 31 | NO | NO |
CVE-2026-58203MEDIUM pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files in a configured secrets_dir. Whe | Jul 6, 2026 | 5.3 | 26 | NO | NO |
CVE-2021-29510HIGH Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to | May 13, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-3772HIGH Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string. | Apr 15, 2024 | 7.5 | 22 | NO | NO |
CVE-2026-25640MEDIUM Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to before 1.51.0, a path traversal vulnerability in the Pydantic AI | Feb 6, 2026 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pydantic.
Media articles that mention a CVE ID that affects a product developed by Pydantic — matched by CVE ID, not by vendor name.