CVE-2021-29510 log

Source
Severity Medium
Remote Yes
Type Denial of service
Description
A security issue has been found in pydantic before version 1.8.2. Passing either 'infinity', 'inf' or float('inf') (or their negatives) to datetime or date fields causes validation to run forever with 100% CPU usage (on one CPU).
Group Package Affected Fixed Severity Status Ticket
AVG-1951 python-pydantic 1.8.1-2 1.8.2-1 Medium Fixed
Date Advisory Group Package Severity Type
25 May 2021 ASA-202105-24 AVG-1951 python-pydantic Medium denial of service
References
https://github.com/samuelcolvin/pydantic/security/advisories/GHSA-5jqp-qgf6-3pvh
https://github.com/samuelcolvin/pydantic/commit/1c24f1d74ba95ea985b50bdc001ce96c813229aa