CVE-2026-107288 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.
Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. allowed_domains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NLow severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
High
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
Low
Confidentiality
I
None
Integrity
A
None
Availability
References
- advisory[email protected]https://github.com/pydantic/pydantic-ai/commit/490335f8e2322e143a79337ddca9410e0176c812
- advisory[email protected]https://github.com/pydantic/pydantic-ai/commit/a9dab92099d0ef9d5d4aa34ccac8a6f1b0e51284
- advisory[email protected]https://github.com/pydantic/pydantic-ai/commit/c1f212a084cbfa0012f2044cdb4731d214b3b983
- advisory[email protected]https://github.com/pydantic/pydantic-ai/pull/8407
- advisory[email protected]https://github.com/pydantic/pydantic-ai/pull/8409
- advisory[email protected]https://github.com/pydantic/pydantic-ai/pull/8421
- advisory[email protected]https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6
- advisory[email protected]https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0
- advisory[email protected]https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-22h6-qm39-v87j
Related threats
same CWE or vendorCVE-2026-107781 — Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerabili…
CVE-2026-107781 · 2h ago
CVE-2026-107394 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.
CVE-2026-107394 · 3h ago
CVE-2026-107698 — FFmpeg before 7.1.4 and 8.0.x before 8.0.2 contains a server-side request forgery vulnerability in ff_rtsp_connect() in libavformat/rtsp.c that fol…
CVE-2026-107698 · 5h ago
CVE-2026-107362 — Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream…
CVE-2026-107362 · 5h ago
PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure
CVE-2026-61430 · 7h ago
CVE-2026-107289 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.
CVE-2026-107289 · 7h ago