ormar
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ormarpage 1 of 1
- CVE-2026-26198HIGHCVSS 7.5EG 7.5✓ Fixed in 0.23.02026-02-24
vulnerable: 0.10.0 ... 0.9.9 (40 versions)
Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by passing user-supplied column names directly into `sqlalchemy.text()` without any validation …
- CVE-2026-27953CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.23.12026-03-19
vulnerable: 0.1.0 ... 0.9.9 (90 versions)
ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing any unauthenticated user to skip all field validation by injecting "__pk_only__": true int…
Check whether ormar is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ormar CVEs against the assets you own.
Start Free Scan →