Package | Installed | Affected | Info |
---|---|---|---|
pydantic | 1.8.1 | >=2.0.0,<2.4.0 , <1.10.13 |
show Regular expression denial of service in Pydanic affected versions allows remote attackers to cause denial of service via a crafted email string. |
pydantic | 1.8.1 | <1.10.2 |
show Pydantic 1.10.2 prevents long strings as int inputs to fix CVE-2020-10735. https://github.com/pydantic/pydantic/commit/eccd85e4d012e70ffbd81f379179da900d4621c5 |
pydantic | 1.8.1 | >=1.8.0a1,<1.8.2 , >=1.7.0a0,<1.7.4 , <1.6.2 |
show Pydantic 1.8.2, 1.7.4 and 1.6.2 include a fix for CVE-2021-29510: In affected versions of Pydantic passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU). Pydantic has been patched with fixes available in the following versions: v1.8.2, v1.7.4, v1.6.2. All these versions are available on pypi(https://pypi.org/project/pydantic/#history), and will be available on conda-forge(https://anaconda.org/conda-forge/pydantic) soon. See the changelog(https://pydantic-docs.helpmanual.io/) for details. If you absolutely can't upgrade, you can work around this risk using a validator(https://pydantic-docs.helpmanual.io/usage/validators/) to catch these values. This is not an ideal solution (in particular you'll need a slightly different function for datetimes), instead of a hack like this you should upgrade pydantic. If you are not using v1.8.x, v1.7.x or v1.6.x and are unable to upgrade to a fixed version of pydantic, please create an issue at https://github.com/samuelcolvin/pydantic/issues requesting a back-port, and we will endeavour to release a patch for earlier versions of pydantic. |
pydantic | 1.8.1 | <1.10.13 , >=2.0a1,<2.4.0 |
show Pydantic 1.10.13 and 2.4.0 include a fix for a regular expression denial of service vulnerability (REDoS). https://github.com/pydantic/pydantic/pull/7360 https://github.com/pydantic/pydantic/pull/7673 |
https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/python-3-shield.svg
[![Python 3](https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/python-3-shield.svg)](https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/)
.. image:: https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/python-3-shield.svg :target: https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/ :alt: Python 3
<a href="https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/"><img src="https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/
{<img src="https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/]
https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/shield.svg
[![Updates](https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/shield.svg)](https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/)
.. image:: https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/shield.svg :target: https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/ :alt: Updates
<a href="https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/"><img src="https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/shield.svg(Updates)!:https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/
{<img src="https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/h0rn3t/fastapi-async-sqlalchemy/]