CVE-2026-107289
Received Received - Intake

IPv6 Zone Identifier Bypass in Pydantic AI

Vulnerability report for CVE-2026-107289, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.56.0 until 1.107.6 and 2.44.0, applications that opt attacker-influenced URLs into local network access through FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True can bypass the cloud-metadata blocklist by appending an IPv6 zone identifier to an IPv6 metadata address. IPv6Address equality and hashing include the zone identifier, so the blocklist comparison fails even though the network stack ignores the zone on a non-link-local destination and reaches the metadata service, potentially exposing cloud IAM credentials. The opt-in settings are disabled by default, and the issue requires an IPv6-enabled environment. This issue is fixed in versions 1.107.6 and 2.44.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
pydantic pydantic-ai >= 1.56.0, < 1.107.6
pydantic pydantic-ai >= 2.0.0b1, < 2.44.0
pydantic pydantic-ai-slim >= 1.56.0, < 1.107.6
pydantic pydantic-ai-slim >= 2.0.0b1, < 2.44.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1289 The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Pydantic AI, a Python agent framework for Generative AI. It allows bypassing cloud-metadata blocklists by appending an IPv6 zone identifier to an IPv6 metadata address. This happens when applications opt into local network access via FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True. The issue arises because IPv6Address equality and hashing include the zone identifier, causing the blocklist check to fail even though the network stack ignores the zone and reaches the metadata service, potentially exposing cloud IAM credentials.

Detection Guidance

Detecting this vulnerability requires checking if your Pydantic AI application is using vulnerable versions (1.56.0 to 1.107.5 or 2.44.0) with enabled local network access features. Inspect your application's dependencies and configuration for Pydantic AI versions in the affected range. Check if FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True is enabled.

Impact Analysis

If you use Pydantic AI in an IPv6-enabled environment with the affected settings enabled, an attacker could trick your application into accessing cloud metadata services by manipulating URLs. This could lead to unauthorized exposure of cloud IAM credentials, potentially allowing attackers to gain control over your cloud resources or data.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR and HIPAA by potentially exposing cloud IAM credentials through an SSRF attack. If exploited, attackers may gain access to sensitive cloud infrastructure, which could lead to unauthorized data access or breaches of confidentiality requirements under these regulations.

Mitigation Strategies

Upgrade Pydantic AI to version 1.107.6 or 2.44.0 or later. If using IPv6, disable the affected features (FileUrl with force_download='allow-local' or web_fetch_tool with allow_local_urls=True) until upgraded. Review network access policies to prevent unauthorized local network access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107289. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart