CVE-2021-29510
published 2021-05-13CVE-2021-29510: Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')`…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.97%
57.8th percentile
Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU). Pydantic has been patched with fixes available in the following versions: v1.8.2, v1.7.4, v1.6.2. All these versions are available on pypi(https://pypi.org/project/pydantic/#history), and will be available on conda-forge(https://anaconda.org/conda-forge/pydantic) soon. See the changelog(https://pydantic-docs.helpmanual.io/) for details. If you absolutely can't upgrade, you can work around this risk using a validator(https://pydantic-docs.helpmanual.io/usage/validators/) to catch these values. This is not an ideal solution (in particular you'll need a slightly different function for datetimes), instead of a hack like this you should upgrade pydantic. If you are not using v1.8.x, v1.7.x or v1.6.x and are unable to upgrade to a fixed version of pydantic, please create an issue at https://github.com/samuelcolvin/pydantic/issues requesting a back-port, and we will endeavour to release a patch for earlier versions of pydantic.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pydantic | < pydantic 1.7.4-1 (bookworm) | pydantic 1.7.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| pydantic | pydantic | < 1.6.2 | 1.6.2 |
| pydantic | pydantic | >= 0 < 1.7.4-1 | 1.7.4-1 |
| pydantic | pydantic | >= 0 < 1.7.4-1 | 1.7.4-1 |
| pydantic | pydantic | >= 0 < 1.7.4-1 | 1.7.4-1 |
| pydantic | pydantic | >= 0 < 1.7.4-1 | 1.7.4-1 |
| pydantic | pydantic | >= 0 < 1.6.2 | 1.6.2 |
| pydantic | pydantic | >= 0 < 1.2-1ubuntu0.1~esm1 | 1.2-1ubuntu0.1~esm1 |
| pydantic | pydantic | >= 1.7 < 1.7.4 | 1.7.4 |
| pydantic | pydantic | >= 1.7 < 1.7.4 | 1.7.4 |
| pydantic | pydantic | >= 1.8 < 1.8.2 | 1.8.2 |
| pydantic | pydantic | >= 1.8 < 1.8.2 | 1.8.2 |
| samuelcolvin | pydantic | < 1.6.2 | 1.6.2 |
| samuelcolvin | pydantic | — | — |
| samuelcolvin | pydantic | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian3.3LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Pydantic vulnerability
vendor_ubuntu·2023-12-12·CVSS 3.3
CVE-2021-29510 [LOW] Pydantic vulnerability
Title: Pydantic vulnerability
Summary: Pydantic could be made to crash if it received specially crafted
input.
Nina Jensen discovered that Pydantic incorrectly handled user input in the
date and datetime fields. An attacker could possibly use this issue to
cause a denial of service via application crash. (CVE-2021-29510)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-29510: pydantic - Pydantic is a data validation and settings management using Python type hinting....
vendor_debian·2021·CVSS 3.3
CVE-2021-29510 [LOW] CVE-2021-29510: pydantic - Pydantic is a data validation and settings management using Python type hinting....
Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU). Pydantic has been patched with fixes available in the following versions: v1.8.2, v1.7.4, v1.6.2. All these versions are available on pypi(https://pypi.org/project/pydantic/#history), and will be available on conda-forge(https://anaconda.org/conda-forge/pydantic) soon. See the changelog(https://pydantic-docs.helpmanual.io/) for details. If you absolutely can't upgrade, you can work around this risk using a validator(https://pydantic-docs.helpmanual.io/usage/validators/) to catch these values. This is not an ideal solut
OSV
pydantic vulnerability
osv·2023-12-12·CVSS 7.5
CVE-2021-29510 [HIGH] pydantic vulnerability
pydantic vulnerability
Nina Jensen discovered that Pydantic incorrectly handled user input in the
date and datetime fields. An attacker could possibly use this issue to
cause a denial of service via application crash. (CVE-2021-29510)
OSV
CVE-2021-29510: Pydantic is a data validation and settings management using Python type hinting
osv·2021-05-13·CVSS 7.5
CVE-2021-29510 [HIGH] CVE-2021-29510: Pydantic is a data validation and settings management using Python type hinting
Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU). Pydantic has been patched with fixes available in the following versions: v1.8.2, v1.7.4, v1.6.2. All these versions are available on pypi(https://pypi.org/project/pydantic/#history), and will be available on conda-forge(https://anaconda.org/conda-forge/pydantic) soon. See the changelog(https://pydantic-docs.helpmanual.io/) for details. If you absolutely can't upgrade, you can work around this risk using a validator(https://pydantic-docs.helpmanual.io/usage/validators/) to catch these values. This is not an ideal solut
OSV
Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
osv·2021-05-13
CVE-2021-29510 [MEDIUM] Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
Impact
Passing either 'infinity', 'inf' or float('inf') (or their negatives) to datetime or date fields causes validation to run forever with 100% CPU usage (on one CPU).
Patches
Pydantic is be patched with fixes available in the following versions:
v1.8.2
v1.7.4
v1.6.2
All these versions are available on pypi, and will be available on conda-forge soon.
See the changelog for details.
Workarounds
If you absolutely can't upgrade, you can work around this risk using a validator to catch these values, brief demo:
from datetime import date
from pydantic import BaseModel, validator
class DemoModel(BaseModel):
date_of_birth: date
@validator('date_of_birth', pre=True)
def skip_infinite_values(cls,
GHSA
Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
ghsa·2021-05-13
CVE-2021-29510 [MEDIUM] CWE-835 Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
Impact
Passing either 'infinity', 'inf' or float('inf') (or their negatives) to datetime or date fields causes validation to run forever with 100% CPU usage (on one CPU).
Patches
Pydantic is be patched with fixes available in the following versions:
v1.8.2
v1.7.4
v1.6.2
All these versions are available on pypi, and will be available on conda-forge soon.
See the changelog for details.
Workarounds
If you absolutely can't upgrade, you can work around this risk using a validator to catch these values, brief demo:
from datetime import date
from pydantic import BaseModel, validator
class DemoModel(BaseModel):
date_of_birth: date
@validator('date_of_birth', pre=True)
def skip_infinite_values(cls,
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/samuelcolvin/pydantic/commit/7e83fdd2563ffac081db7ecdf1affa65ef38c468https://github.com/samuelcolvin/pydantic/security/advisories/GHSA-5jqp-qgf6-3pvhhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S2HT266L6Q7H6ICP7DFGXOGBJHNNKMKB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UEFWM7DYKD2ZHE7R5YT5EQWJPV4ZKYRB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UMKAJX4O6IGBBCE32CO2G7PZQCCQSBLV/https://github.com/samuelcolvin/pydantic/commit/7e83fdd2563ffac081db7ecdf1affa65ef38c468https://github.com/samuelcolvin/pydantic/security/advisories/GHSA-5jqp-qgf6-3pvhhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S2HT266L6Q7H6ICP7DFGXOGBJHNNKMKB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UEFWM7DYKD2ZHE7R5YT5EQWJPV4ZKYRB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UMKAJX4O6IGBBCE32CO2G7PZQCCQSBLV/
2021-05-13
Published