3.7

CVE-2026-107288

Pydantic AI: web_fetch_tool blocked_domains bypass via a hostname the resolver normalizes differently

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. allowed_domains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerpydantic
≫
Produkt pydantic-ai
Version >= 1.77.0, < 1.107.6
Status affected
Version >= 2.0.0b1, < 2.44.0
Status affected
Herstellerpydantic
≫
Produkt pydantic-ai-slim
Version >= 1.77.0, < 1.107.6
Status affected
Version >= 2.0.0b1, < 2.44.0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.297
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-1289 Improper Validation of Unsafe Equivalence in Input

The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.

CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-22h6-qm39-v87j
https://github.com/pydantic/pydantic-ai/pull/8407
https://github.com/pydantic/pydantic-ai/pull/8409
https://github.com/pydantic/pydantic-ai/pull/8421
https://github.com/pydantic/pydantic-ai/commit/490335f8e2322e143a79337ddca9410e0176c812
https://github.com/pydantic/pydantic-ai/commit/a9dab92099d0ef9d5d4aa34ccac8a6f1b0e51284
https://github.com/pydantic/pydantic-ai/commit/c1f212a084cbfa0012f2044cdb4731d214b3b983
https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6
https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0