{"id":"UBUNTU-CVE-2026-58203","details":"pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files in a configured secrets_dir. When secrets_nested_subdir=True, a directory entry inside secrets_dir that is a symbolic link pointing outside secrets_dir is followed, so files outside the configured directory are read into settings values. The same code path bypasses the documented secrets_dir_max_size protection. An attacker or lower-privileged component able to influence entries in the configured secrets directory (for example, a writable or shared secrets mount) can turn this into an unintended local file read into settings and can defeat the advertised loading-size cap. This vulnerability is fixed in 2.14.2.","modified":"2026-07-09T17:17:12.900655432Z","published":"2026-07-06T16:16:00Z","upstream":["CVE-2026-58203"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-58203"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-58203"},{"type":"REPORT","url":"https://github.com/pydantic/pydantic-settings/security/advisories/GHSA-4xgf-cpjx-pc3j"}],"affected":[{"package":{"name":"pydantic-settings","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/pydantic-settings?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.8.1-1","2.8.1-2"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-pydantic-settings","binary_version":"2.8.1-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58203.json"}},{"package":{"name":"pydantic-settings","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/pydantic-settings?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.8.1-2","2.12.0-2","2.13.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-pydantic-settings","binary_version":"2.13.0-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-58203.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"Ubuntu","score":"medium"}]}