UbuntuUpdates.org

Package "python3-dynaconf"

Name: python3-dynaconf

Description:

Easy and Powerful Settings Configuration for Python

Latest version: 3.1.7-2ubuntu0.25.10.1
Release: questing (25.10)
Level: security
Repository: universe
Head package: python-dynaconf
Homepage: https://github.com/rochacbruno/dynaconf

Links


Download "python3-dynaconf"


Other versions of "python3-dynaconf" in Questing

Repository Area Version
base universe 3.1.7-2
updates universe 3.1.7-2ubuntu0.25.10.1

Changelog

Version: 3.1.7-2ubuntu0.25.10.1 2026-05-06 16:08:04 UTC

  python-dynaconf (3.1.7-2ubuntu0.25.10.1) questing-security; urgency=medium

  * SECURITY UPDATE: Remote code execution via insecure template evaluator
  - debian/patches/CVE-2026-33154.patch: use Jinja2 SandboxedEnvironment when
    evaluating environment variables in the formatter.
  - CVE-2026-33154

 -- Federico Quattrin <email address hidden> Tue, 05 May 2026 04:26:02 -0300

CVE-2026-33154 dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due



About   -   Send Feedback to @ubuntu_updates