dynaconf
Configuration Management for Python ⚙
Activity
- Latest release
- 1mo ago
- Total releases
- 100
- Cadence
- ~22 days
- Last 12 months
- 8
Reach
- Stars
- 4.3k
Details
- License
- MIT
- First release
- Aug 14, 2015
| Version | Released | |
|---|---|---|
3.3.5
patch
| ||
3.3.4
patch
| ||
3.3.3
patch
| ||
3.3.2
patch
| ||
3.3.1
patch
| ||
3.3.0
minor
| ||
3.2.13
patch
| ||
3.2.12
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.11
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.10
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.9
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.8
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.7
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.6
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.5
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.4
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.3
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.2
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.1
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.0
minor
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.12
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.11
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.10
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.9
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.8
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.7
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.5
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.4
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.3
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.3rc1
pre
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.2
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.1
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.1rc6
pre
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.1rc5
pre
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.1rc4
pre
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.1rc3
pre
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.1rc2
pre
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.1rc1
pre
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.0
minor
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.0.0
major
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.0.0rc2
pre
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
3.0.0rc1
pre
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.2.3
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.2.2
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.2.1
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.4
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.3
patch
1 CVE
CVE-2026-33154
PYSEC-2026-2147
GHSA-pxrr-hq57-q35p
Mar 20, 2026
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.10
0.2.11
0.2.12
0.2.13
0.2.2
0.2.3
0.2.4
+ 81 more Show less
0.2.5
0.2.6
0.2.8
0.2.9
0.3.0
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.1.0
1.2.0
1.2.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.1
3.1.10
3.1.11
3.1.12
3.1.1rc1
3.1.1rc2
3.1.1rc3
3.1.1rc4
3.1.1rc5
3.1.1rc6
3.1.2
3.1.3
3.1.3rc1
3.1.4
3.1.5
3.1.7
3.1.8
3.1.9
3.2.0
3.2.1
3.2.10
3.2.11
3.2.12
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
Fixed in
3.2.13
References Updated Jul 13, 2026 · Source: OSV.dev |