Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-33154

Опубликовано: 20 мар. 2026
Источник: debian
EPSS Низкий

Описание

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-dynaconffixed3.2.13-1package
python-dynaconffixed3.1.7-2+deb13u1trixiepackage
python-dynaconfpostponedbookwormpackage
python-dynaconfpostponedbullseyepackage

Примечания

  • https://github.com/dynaconf/dynaconf/security/advisories/GHSA-pxrr-hq57-q35p

  • Fixed by: https://github.com/dynaconf/dynaconf/commit/2fbb45ee36b8c0caa5b924fe19f3c1a5e8603fa7 (3.2.13)

EPSS

Процентиль: 42%
0.00526
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.

CVSS3: 7.5
redhat
5 месяцев назад

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.

CVSS3: 7.5
nvd
5 месяцев назад

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.

suse-cvrf
5 месяцев назад

Security update for python-dynaconf

CVSS3: 7.5
github
5 месяцев назад

dynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja Resolver

EPSS

Процентиль: 42%
0.00526
Низкий