MEDIUM SEVERITYCONFIRMED
model_copy(update=) bypasses all validators
Package
pydantic
Version
2.12.5
Verified
2026-03-28
Description
Using `model_copy(update={...})` bypasses all field validators and `model_validator` logic. Fields that would fail validation during construction (negative balance, None for required field) are silently accepted when set via `model_copy(update=)`.
Reproduction
# account = Account(balance=1000.0, account_id='acc123')
# copy = account.model_copy(update={'balance': -99999.0, 'account_id': None})
# copy.balance == -99999.0 # True — validators bypassed