UbuntuUpdates.org

Package "python-dynaconf"

Name: python-dynaconf

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Easy and Powerful Settings Configuration for Python

Latest version: 3.1.7-2ubuntu0.24.04.1
Release: noble (24.04)
Level: updates
Repository: universe

Links



Other versions of "python-dynaconf" in Noble

Repository Area Version
base universe 3.1.7-2
security universe 3.1.7-2ubuntu0.24.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.1.7-2ubuntu0.24.04.1 2026-05-06 17:08:31 UTC

  python-dynaconf (3.1.7-2ubuntu0.24.04.1) noble-security; urgency=medium

  * SECURITY UPDATE: Remote code execution via insecure template evaluator
  - debian/patches/CVE-2026-33154.patch: use Jinja2 SandboxedEnvironment when
    evaluating environment variables in the formatter.
  - CVE-2026-33154

 -- Federico Quattrin <email address hidden> Tue, 05 May 2026 04:25:21 -0300

CVE-2026-33154 dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due



About   -   Send Feedback to @ubuntu_updates