CVE-2026-107288
Received Received - Intake

Web Fetch Tool IDNA Spoofing in Pydantic AI

Vulnerability report for CVE-2026-107288, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. allowed_domains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
pydantic pydantic-ai >= 1.77.0, < 1.107.6
pydantic pydantic-ai >= 2.0.0b1, < 2.44.0
pydantic pydantic-ai-slim >= 1.77.0, < 1.107.6
pydantic pydantic-ai-slim >= 2.0.0b1, < 2.44.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1289 The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107288 affects Pydantic AI versions between 1.77.0 and 1.107.5 and 2.0.0b1 to 2.43.9. It involves the web_fetch_tool component which uses a blocked_domains list to restrict access. The tool fails to normalize hostnames before comparison, allowing bypasses through alternative spellings like fullwidth characters or IDNA encodings that resolve to blocked hosts but don't match the configured string exactly. This lets attackers bypass domain restrictions using visually similar but technically different hostnames.

Detection Guidance

Check if your pydantic-ai version is between 1.77.0-1.107.5 or 2.0.0b1-2.43.9. Run: pip show pydantic-ai. If affected, upgrade to 1.107.6 or 2.44.0. Monitor network logs for unusual outbound requests to blocked domains using tools like tcpdump or Wireshark.

Impact Analysis

An attacker could trick the application into fetching content from a blocked domain by using alternative spellings or encodings that resolve to the same host. Since the application uses its own privileges to fetch the content, this could expose sensitive data or enable further attacks. The impact is limited to what the blocked domain discloses, and private-IP and cloud-metadata protections remain effective.

Compliance Impact

The vulnerability could potentially lead to unauthorized data exfiltration by bypassing domain restrictions, which may violate data protection requirements under GDPR (e.g., unauthorized access to personal data) or HIPAA (e.g., unauthorized access to protected health information). However, the impact is limited as the application's privileges are used for fetching, and private-IP/cloud-metadata protections remain effective.

Mitigation Strategies
  • Upgrade pydantic-ai to version 1.107.6 or 2.44.0 or later to patch the vulnerability.
  • If upgrading is not immediately possible, switch from blocked_domains to allowed_domains in web_fetch_tool to enforce a default-deny policy.
  • Reject non-ASCII hostnames in input processing before they reach the web_fetch_tool to prevent IDNA-based bypasses.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107288. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart