USN-8231-1

Advisory lineage Upstream: 2 Downstream: 0
Published: 06 May 2026, 09:06
Last modified:07 May 2026, 14:14

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 May 2026, 09:06
Published
Vulnerability first disclosed
07 May 2026, 14:14
Last Modified
Vulnerability information updated

Description

python-dynaconf vulnerability It was discovered that Dynaconf was incorrectly handling template evaluation in its string resolvers. A remote attacker could possibly use this issue to execute arbitrary code.

Affected Systems

  • ubuntupython-dynaconf

    < 3.1.7-1ubuntu0.1~esm1 | < 3.1.7-2ubuntu0.24.04.1 | < 3.1.7-2ubuntu0.25.10.1 | < 3.2.12-1ubuntu0.1~esm1

References (2)