6.8
CVE-2026-107289
- EPSS 0.33%
- Veröffentlicht 08.10.2026 15:20:18
- Zuletzt bearbeitet 08.10.2026 20:35:31
- Erkennungen
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifier (incomplete fix for CVE-2026-46678 and CVE-2026-48782)
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.56.0 until 1.107.6 and 2.44.0, applications that opt attacker-influenced URLs into local network access through FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True can bypass the cloud-metadata blocklist by appending an IPv6 zone identifier to an IPv6 metadata address. IPv6Address equality and hashing include the zone identifier, so the blocklist comparison fails even though the network stack ignores the zone on a non-link-local destination and reaches the metadata service, potentially exposing cloud IAM credentials. The opt-in settings are disabled by default, and the issue requires an IPv6-enabled environment. This issue is fixed in versions 1.107.6 and 2.44.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerpydantic
≫
Produkt
pydantic-ai
Version
>= 1.56.0, < 1.107.6
Status
affected
Version
>= 2.0.0b1, < 2.44.0
Status
affected
Herstellerpydantic
≫
Produkt
pydantic-ai-slim
Version
>= 1.56.0, < 1.107.6
Status
affected
Version
>= 2.0.0b1, < 2.44.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.239 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.8 | 2.2 | 4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
|
CWE-1289 Improper Validation of Unsafe Equivalence in Input
The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6
https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0
https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-vmxc-h2x2-jmf3
https://github.com/pydantic/pydantic-ai/pull/8401
https://github.com/pydantic/pydantic-ai/pull/8402
https://github.com/pydantic/pydantic-ai/commit/02157e1b87bd45d3f2e111ce07afdf89f9fb0e5b
https://github.com/pydantic/pydantic-ai/commit/4da70591460f51a8c4f128eaeef70a33340dbd55