pydantic-settings
Settings management using pydantic
Activity
- Latest release
- 1mo ago
- Total releases
- 45
- Cadence
- ~18 days
- Last 12 months
- 7
Reach
- Stars
- 1.4k
Details
- License
- MIT
- First release
- Aug 19, 2019
| Version | Released | |
|---|---|---|
2.15.0
minor
| ||
2.14.2
patch
| ||
2.14.1
patch
1 CVE
CVE-2026-58203
GHSA-4xgf-cpjx-pc3j
Jun 19, 2026
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
5.3
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
Low
Summary
Details
Because the two passes disagreed on symlinks, a symlinked directory inside
ReproductionIn a clean Linux container, with a
On affected versions, ImpactApplications that opt into
The vulnerability requires the ability to place a symbolic link inside the configured secrets directory; it is not remotely reachable on its own. Applications that do not use MitigationUpgrade to pydantic-settings 2.14.2, which:
If upgrading is not immediately possible, ensure the configured Affected versions
2.12.0
2.13.0
2.13.1
2.14.0
2.14.1
Fixed in
2.14.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.14.0
minor
1 CVE
CVE-2026-58203
GHSA-4xgf-cpjx-pc3j
Jun 19, 2026
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
5.3
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
Low
Summary
Details
Because the two passes disagreed on symlinks, a symlinked directory inside
ReproductionIn a clean Linux container, with a
On affected versions, ImpactApplications that opt into
The vulnerability requires the ability to place a symbolic link inside the configured secrets directory; it is not remotely reachable on its own. Applications that do not use MitigationUpgrade to pydantic-settings 2.14.2, which:
If upgrading is not immediately possible, ensure the configured Affected versions
2.12.0
2.13.0
2.13.1
2.14.0
2.14.1
Fixed in
2.14.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.13.1
patch
1 CVE
CVE-2026-58203
GHSA-4xgf-cpjx-pc3j
Jun 19, 2026
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
5.3
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
Low
Summary
Details
Because the two passes disagreed on symlinks, a symlinked directory inside
ReproductionIn a clean Linux container, with a
On affected versions, ImpactApplications that opt into
The vulnerability requires the ability to place a symbolic link inside the configured secrets directory; it is not remotely reachable on its own. Applications that do not use MitigationUpgrade to pydantic-settings 2.14.2, which:
If upgrading is not immediately possible, ensure the configured Affected versions
2.12.0
2.13.0
2.13.1
2.14.0
2.14.1
Fixed in
2.14.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.13.0
minor
1 CVE
CVE-2026-58203
GHSA-4xgf-cpjx-pc3j
Jun 19, 2026
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
5.3
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
Low
Summary
Details
Because the two passes disagreed on symlinks, a symlinked directory inside
ReproductionIn a clean Linux container, with a
On affected versions, ImpactApplications that opt into
The vulnerability requires the ability to place a symbolic link inside the configured secrets directory; it is not remotely reachable on its own. Applications that do not use MitigationUpgrade to pydantic-settings 2.14.2, which:
If upgrading is not immediately possible, ensure the configured Affected versions
2.12.0
2.13.0
2.13.1
2.14.0
2.14.1
Fixed in
2.14.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.12.0
minor
1 CVE
CVE-2026-58203
GHSA-4xgf-cpjx-pc3j
Jun 19, 2026
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
5.3
/ 10
Medium
Local
Low
Low
None
Unchanged
Low
Low
Low
Summary
Details
Because the two passes disagreed on symlinks, a symlinked directory inside
ReproductionIn a clean Linux container, with a
On affected versions, ImpactApplications that opt into
The vulnerability requires the ability to place a symbolic link inside the configured secrets directory; it is not remotely reachable on its own. Applications that do not use MitigationUpgrade to pydantic-settings 2.14.2, which:
If upgrading is not immediately possible, ensure the configured Affected versions
2.12.0
2.13.0
2.13.1
2.14.0
2.14.1
Fixed in
2.14.2
References Updated Sep 10, 2026 · Source: OSV.dev | ||
2.11.0
minor
| ||
2.10.1
patch
| ||
2.10.0
minor
| ||
2.9.1
patch
| ||
2.9.0
minor
| ||
2.8.1
patch
| ||
2.8.0
minor
| ||
2.7.1
patch
| ||
2.7.0
minor
| ||
2.6.1
patch
| ||
2.6.0
minor
| ||
2.5.2
patch
| ||
2.5.1
patch
| ||
2.5.0
minor
| ||
2.4.0
minor
| ||
2.3.4
patch
| ||
2.3.3
patch
| ||
2.3.2
patch
| ||
2.3.1
patch
| ||
2.3.0
minor
| ||
2.2.1
patch
| ||
2.2.0
minor
| ||
2.1.0
minor
| ||
2.0.3
patch
| ||
2.0.2
patch
| ||
2.0.1
patch
| ||
2.0.0
major
| ||
2.0b2
pre
| ||
2.0b1
pre
| ||
2.0a4
pre
| ||
2.0a3
pre
| ||
1.99
major
| ||
2.0a1
pre
| ||
0.2.5
initial
| ||
0.1.2b0
pre
| ||
0.1.1b0
pre
| ||
0.1.0a2
pre
| ||
0.1.0a1
pre
|