Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30431
HistoryMay 14, 2021 - 4:33 a.m.

Denial Of Service (DoS)

2021-05-1404:33:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
34
pydantic
denial of service
vulnerability
cpu loop
software

EPSS

0.002

Percentile

54.8%

pydantic is vulnerable to denial of service. An attacker is able to exploit the vulnerability by passing either infinity , inf or float(inf) (or their negatives) to datetimeor data` fields causing the validaton to run in loops with 100% CPU usage.