Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2233237
AlmaLinux
5964
Alpaquita
16148
Alpine
4635
Android
3677
Azure Linux
17766
BellSoft Hardened Containers
764
Bitnami
9476
Chainguard
1043402
CleanStart
5235
CRAN
14
crates.io
2748
Debian
68825
Echo
7749
GHC
3
GIT
108734
GitHub Actions
55
Go
9319
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7048
MinimOS
147720
npm
229081
NuGet
1869
opam
29
openEuler
8900
openSUSE
14526
OSS-Fuzz
4015
Packagist
7100
Pub
11
PyPI
25416
Red Hat
23506
Rocky Linux
4334
Root
19620
RubyGems
5326
SUSE
23403
SwiftURL
60
TuxCare
9810
Ubuntu
65806
VSCode
21
Wolfi
292800
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3693
PyPI/pydantic-ai-slim
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
19 Aug
Fix available
Severity - 6.8 (Medium)
GHSA-h7p7-w5gc-xj3w
PyPI/pydantic-ai
PyPI/pydantic-ai-slim
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
13 Aug
Fix available
Severity - 6.8 (Medium)
PYSEC-2026-2981
PyPI/pydantic-ai-slim
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
13 Jul
Fix available
Severity - 6.8 (Medium)
PYSEC-2026-2982
PyPI/pydantic-ai-slim
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
13 Jul
Fix available
Severity - 6.8 (Medium)
PYSEC-2026-2983
PyPI/pydantic-ai-slim
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL
13 Jul
Fix available
Severity - 7.1 (High)
PYSEC-2026-2980
PyPI/pydantic-ai-slim
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
13 Jul
Fix available
Severity - 8.6 (High)
GHSA-cg7w-rg45-pc59
PyPI/pydantic-ai
PyPI/pydantic-ai-slim
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
26 Jun
Fix available
Severity - 6.8 (Medium)
GHSA-cqp8-fcvh-x7r3
PyPI/pydantic-ai
PyPI/pydantic-ai-slim
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
21 May
Fix available
Severity - 6.8 (Medium)
GHSA-wjp5-868j-wqv7
PyPI/pydantic-ai
PyPI/pydantic-ai-slim
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL
06 Feb
Fix available
Severity - 7.1 (High)
GHSA-2jrp-274c-jhv3
PyPI/pydantic-ai
PyPI/pydantic-ai-slim
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
06 Feb
Fix available
Severity - 8.6 (High)
PyPI - OSV