Version 2.12.4-1 of pydantic is marked for autoremoval from testing on Fri 02 Jan 2026. It depends (transitively) on pydantic-core, affected by #1121035. You should try to prevent the removal by fixing these RC bugs.
debian/patches: 1 patch with invalid metadata
high
Among the 1 debian patch
available in version 2.12.4-1 of the package,
we noticed the following issues:
1 patch with
invalid metadata that ought to be fixed.
1 issue left for the package maintainer to handle:
CVE-2024-3772:
(needs triaging)
Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.