USN-8231-1
Advisory lineage Upstream: 2 Downstream: 0
Upstream
Published: 06 May 2026, 09:06
Last modified:07 May 2026, 14:14
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
06 May 2026, 09:06
Published
Vulnerability first disclosed
07 May 2026, 14:14
Last Modified
Vulnerability information updated
Description
python-dynaconf vulnerability It was discovered that Dynaconf was incorrectly handling template evaluation in its string resolvers. A remote attacker could possibly use this issue to execute arbitrary code.
Affected Systems
- ubuntu•python-dynaconf
< 3.1.7-1ubuntu0.1~esm1 | < 3.1.7-2ubuntu0.24.04.1 | < 3.1.7-2ubuntu0.25.10.1 | < 3.2.12-1ubuntu0.1~esm1