VDB
Sign up
MEDIUM5.9

PYSEC-2026-1812

Pydantic regular expression denial of service

Quick fix

PYSEC-2026-1812 — pydantic: upgrade to the fixed version with the command below.

pip install --upgrade 'pydantic>=1.10.13'

Details

Regular expression denial of service in Pydantic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pydantic
Introduced in: 0Fixed in: 1.10.13
Fixpip install --upgrade 'pydantic>=1.10.13'

References