MEDIUM SEVERITYCONFIRMED

model_copy(update=) bypasses all validators

Package
pydantic
Version
2.12.5
Verified
2026-03-28

Description

Using `model_copy(update={...})` bypasses all field validators and `model_validator` logic. Fields that would fail validation during construction (negative balance, None for required field) are silently accepted when set via `model_copy(update=)`.

Reproduction

# account = Account(balance=1000.0, account_id='acc123')
# copy = account.model_copy(update={'balance': -99999.0, 'account_id': None})
# copy.balance == -99999.0  # True — validators bypassed
← All bugsScan your code →