<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:47:22.505498+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-04697</id>
    <title>bdu:2021-04697</title>
    <updated>2026-10-03T20:47:22.665579+00:00</updated>
    <content>bdu:2021-04697</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-04697"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-pydantic-cve-2021-29510</id>
    <title>BREW-pydantic-CVE-2021-29510 — Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic</title>
    <updated>2026-10-03T20:47:22.665626+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: pydantic</p>
<p>Impact</p>
<p>Passing either 'infinity', 'inf' or float('inf') (or their negatives) to datetime or date fields causes validation to run forever with 100% CPU usage (on one CPU).
Patches</p>
<p>Pydantic is be patched with fixes available in the following versions:</p>
<p>v1.8.2
    v1.7.4
    v1.6.2</p>
<p>All these versions are available on pypi, and will be available on conda-forge soon.</p>
<p>See the changelog for details.
Workarounds</p>
<p>If you absolutely can't upgrade, you can work around this risk using a validator to catch these values, brief demo:</p>
<p>from datetime import date
from pydantic import BaseModel, validator</p>
<p>class DemoModel(BaseModel):
    date_of_birth: date</p>
<p>@validator('date_of_birth', pre=True)
    def skip_infinite_values(cls, v):
        try:
            seconds = float(v)
        except (ValueError, TypeError):
            return v
        else:
            if seconds == float('inf'):
                return date.max
            elif seconds == float('-inf'):
                return date.min
            else:
                return seconds</p>
<p>Note: this is not an ideal solution (in particular you'll need a slightly different function for datetimes), instead of a hack like this you should upgrade pydantic.</p>
<p>If you are not using v1.8.x, v1.7.x or v1.6.x and are unable to upgrade to a fixed version of pydantic, please create an issue requesting a back-port, and we will endeavour to release a patch for earlier versions of pydantic.
References</p>
<p>This was fixed in commit 7e83fdd.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-pydantic-cve-2021-29510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-26401</id>
    <title>EUVD-2026-26401</title>
    <updated>2026-10-03T20:47:22.665719+00:00</updated>
    <content>EUVD-2026-26401</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-26401"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-29510</id>
    <title>fkie_cve-2021-29510</title>
    <updated>2026-10-03T20:47:22.665744+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU). Pydantic has been patched with fixes available in the following versions: v1.8.2, v1.7.4, v1.6.2. All these versions are available on pypi(https://pypi.org/project/pydantic/#history), and will be available on conda-forge(https://anaconda.org/conda-forge/pydantic) soon. See the changelog(https://pydantic-docs.helpmanual.io/) for details. If you absolutely can't upgrade, you can work around this risk using a validator(https://pydantic-docs.helpmanual.io/usage/validators/) to catch these values. This is not an ideal solution (in particular you'll need a slightly different function for datetimes), instead of a hack like this you should upgrade pydantic. If you are not using v1.8.x, v1.7.x or v1.6.x and are unable to upgrade to a fixed version of pydantic, please create an issue at https://github.com/samuelcolvin/pydantic/issues requesting a back-port, and we will endeavour to release a patch for earlier versions of pydantic.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-29510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5jqp-qgf6-3pvh</id>
    <title>GHSA-5jqp-qgf6-3pvh — Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic</title>
    <updated>2026-10-03T20:47:22.665795+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pydantic</p>
<p>Impact</p>
<p>Passing either 'infinity', 'inf' or float('inf') (or their negatives) to datetime or date fields causes validation to run forever with 100% CPU usage (on one CPU).
Patches</p>
<p>Pydantic is be patched with fixes available in the following versions:</p>
<p>v1.8.2
    v1.7.4
    v1.6.2</p>
<p>All these versions are available on pypi, and will be available on conda-forge soon.</p>
<p>See the changelog for details.
Workarounds</p>
<p>If you absolutely can't upgrade, you can work around this risk using a validator to catch these values, brief demo:</p>
<p>from datetime import date
from pydantic import BaseModel, validator</p>
<p>class DemoModel(BaseModel):
    date_of_birth: date</p>
<p>@validator('date_of_birth', pre=True)
    def skip_infinite_values(cls, v):
        try:
            seconds = float(v)
        except (ValueError, TypeError):
            return v
        else:
            if seconds == float('inf'):
                return date.max
            elif seconds == float('-inf'):
                return date.min
            else:
                return seconds</p>
<p>Note: this is not an ideal solution (in particular you'll need a slightly different function for datetimes), instead of a hack like this you should upgrade pydantic.</p>
<p>If you are not using v1.8.x, v1.7.x or v1.6.x and are unable to upgrade to a fixed version of pydantic, please create an issue requesting a back-port, and we will endeavour to release a patch for earlier versions of pydantic.
References</p>
<p>This was fixed in commit 7e83fdd.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5jqp-qgf6-3pvh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-29510</id>
    <title>gsd-2021-29510</title>
    <updated>2026-10-03T20:47:22.665862+00:00</updated>
    <content>gsd-2021-29510</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-29510"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11254-1</id>
    <title>openSUSE-SU-2024:11254-1 — python36-pydantic-1.8.2-1.2 on GA media</title>
    <updated>2026-10-03T20:47:22.665884+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python36-pydantic-1.8.2-1.2 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11254-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2021-47</id>
    <title>PYSEC-2021-47</title>
    <updated>2026-10-03T20:47:22.665916+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pydantic</p>
<p>Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU). Pydantic has been patched with fixes available in the following versions: v1.8.2, v1.7.4, v1.6.2. All these versions are available on pypi(https://pypi.org/project/pydantic/#history), and will be available on conda-forge(https://anaconda.org/conda-forge/pydantic) soon. See the changelog(https://pydantic-docs.helpmanual.io/) for details. If you absolutely can't upgrade, you can work around this risk using a validator(https://pydantic-docs.helpmanual.io/usage/validators/) to catch these values. This is not an ideal solution (in particular you'll need a slightly different function for datetimes), instead of a hack like this you should upgrade pydantic. If you are not using v1.8.x, v1.7.x or v1.6.x and are unable to upgrade to a fixed version of pydantic, please create an issue at https://github.com/samuelcolvin/pydantic/issues requesting a back-port, and we will endeavour to release a patch for earlier versions of pydantic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2021-47"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-29510</id>
    <title>UBUNTU-CVE-2021-29510</title>
    <updated>2026-10-03T20:47:22.665971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: pydantic</p>
<p>Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU). Pydantic has been patched with fixes available in the following versions: v1.8.2, v1.7.4, v1.6.2. All these versions are available on pypi(https://pypi.org/project/pydantic/#history), and will be available on conda-forge(https://anaconda.org/conda-forge/pydantic) soon. See the changelog(https://pydantic-docs.helpmanual.io/) for details. If you absolutely can't upgrade, you can work around this risk using a validator(https://pydantic-docs.helpmanual.io/usage/validators/) to catch these values. This is not an ideal solution (in particular you'll need a slightly different function for datetimes), instead of a hack like this you should upgrade pydantic. If you are not using v1.8.x, v1.7.x or v1.6.x and are unable to upgrade to a fixed version of pydantic, please create an issue at https://github.com/samuelcolvin/pydantic/issues requesting a back-port, and we will endeavour to release a patch for earlier versions of pydantic.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-29510"/>
  </entry>
</feed>
