VDB
KO
MEDIUM 5.9

GHSA-mr82-8j83-vxmv

Pydantic regular expression denial of service

Details

Regular expression denial of service in Pydantic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / pydantic
Introduced in: 2.0.0 Fixed in: 2.4.0
Fix pip install --upgrade 'pydantic>=2.4.0'
PyPI / pydantic
Introduced in: 0 Fixed in: 1.10.13
Fix pip install --upgrade 'pydantic>=1.10.13'

References