{"id":"GHSA-vmxc-h2x2-jmf3","summary":"Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers","details":"### Summary\n\nWhen an application using Pydantic AI opts a URL into local network access — either a `FileUrl` with `force_download='allow-local'`, or `web_fetch_tool(allow_local_urls=True)` — the cloud-metadata blocklist could be bypassed by appending an IPv6 zone identifier to a metadata address (for example `fd00:ec2::254%251`). The host ignores the zone identifier on a destination that is not link-local and delivers the request to the metadata endpoint anyway, exposing cloud IAM short-term credentials.\n\nThis is an incomplete fix of [GHSA-cqp8-fcvh-x7r3](https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-cqp8-fcvh-x7r3) / [CVE-2026-46678](https://nvd.nist.gov/vuln/detail/CVE-2026-46678) and [GHSA-cg7w-rg45-pc59](https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-cg7w-rg45-pc59) / [CVE-2026-48782](https://nvd.nist.gov/vuln/detail/CVE-2026-48782), themselves follow-ups to [CVE-2026-25580](https://nvd.nist.gov/vuln/detail/CVE-2026-25580). The parent advisory's remediation guaranteed that cloud metadata endpoints are always blocked, even with local access allowed. That guarantee did not hold for zone-scoped spellings of the IPv6 metadata endpoints.\n\n\n### Details\n\nThe cloud-metadata guard compared IPv6 addresses against its blocklist by set membership. Python includes the zone identifier in `IPv6Address` equality and hashing, so a zone-scoped spelling of a blocked address did not match, while the network stack ignores the zone identifier for a destination that is not link-local. The private-range checks, and the IPv4 and transition-form metadata checks, were already unaffected, because they compare by network containment and by packed bytes respectively.\n\nOnly the IPv6 cloud metadata endpoints were reachable this way, so the issue requires an IPv6-enabled environment — for example AWS EC2 or EKS with IPv6, GCP IPv6-only instances, or Scaleway.\n\n### Who Is Affected\n\nYou are affected **only if** your application opts a URL that is, or could be, influenced by untrusted input into local network access, through either:\n\n- a `FileUrl` (`ImageUrl`, `AudioUrl`, `VideoUrl`, `DocumentUrl`) with `force_download='allow-local'`; or\n- `web_fetch_tool(allow_local_urls=True)`, where the model chooses the URL.\n\nBoth are off by default.\n\nYou are **not** affected through the `FileUrl` path if you use any of the bundled integrations to ingest user input, because they do not propagate `force_download` from external data:\n\n- `Agent.to_web` / `clai web`\n- `VercelAIAdapter`\n- `AGUIAdapter` / `Agent.to_ag_ui`\n\n`web_fetch_tool` is configured by your own application, so a client cannot turn on `allow_local_urls`.\n\nApplications that only download from developer-controlled URLs are not affected.\n\n### Remediation\n\nUpgrade to a patched version. The cloud-metadata and private-IP checks now drop an IPv6 zone identifier before evaluating the address, so every blocklist comparison is made on the address itself. A zone identifier is still carried on the connection, so legitimate link-local fetches under local network access continue to work.\n\n### Workaround for Unpatched Versions\n\nAvoid opting into local network access — `force_download='allow-local'` or `web_fetch_tool(allow_local_urls=True)` — on any URL that could be influenced by untrusted input. If you must, reject URL hosts containing `%` before constructing the `FileUrl` or configuring the tool.\n\n### Credits\n\nReported by [@euriconicacio](https://github.com/euriconicacio).","aliases":["CVE-2026-107289"],"modified":"2026-10-08T17:00:11.101141800Z","published":"2026-10-08T16:48:06Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-08T16:48:06Z","nvd_published_at":null,"cwe_ids":["CWE-1289","CWE-918"]},"references":[{"type":"WEB","url":"https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-vmxc-h2x2-jmf3"},{"type":"WEB","url":"https://github.com/pydantic/pydantic-ai/pull/8401"},{"type":"WEB","url":"https://github.com/pydantic/pydantic-ai/pull/8402"},{"type":"WEB","url":"https://github.com/pydantic/pydantic-ai/commit/02157e1b87bd45d3f2e111ce07afdf89f9fb0e5b"},{"type":"WEB","url":"https://github.com/pydantic/pydantic-ai/commit/4da70591460f51a8c4f128eaeef70a33340dbd55"},{"type":"PACKAGE","url":"https://github.com/pydantic/pydantic-ai"},{"type":"WEB","url":"https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6"},{"type":"WEB","url":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0"}],"affected":[{"package":{"name":"pydantic-ai","ecosystem":"PyPI","purl":"pkg:pypi/pydantic-ai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.56.0"},{"fixed":"1.107.6"}]}],"versions":["1.100.0","1.101.0","1.102.0","1.103.0","1.104.0","1.105.0","1.106.0","1.107.0","1.107.1","1.107.2","1.107.4","1.107.5","1.56.0","1.57.0","1.58.0","1.59.0","1.60.0","1.61.0","1.62.0","1.63.0","1.64.0","1.65.0","1.66.0","1.67.0","1.68.0","1.69.0","1.70.0","1.71.0","1.72.0","1.73.0","1.74.0","1.75.0","1.76.0","1.77.0","1.78.0","1.79.0","1.80.0","1.81.0","1.82.0","1.83.0","1.84.0","1.84.1","1.85.0","1.85.1","1.86.0","1.86.1","1.87.0","1.88.0","1.89.0","1.89.1","1.90.0","1.91.0","1.92.0","1.93.0","1.94.0","1.95.0","1.95.1","1.96.0","1.96.1","1.97.0","1.98.0","1.99.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-vmxc-h2x2-jmf3/GHSA-vmxc-h2x2-jmf3.json"}},{"package":{"name":"pydantic-ai","ecosystem":"PyPI","purl":"pkg:pypi/pydantic-ai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0b1"},{"fixed":"2.44.0"}]}],"versions":["2.0.0","2.0.0b1","2.0.0b2","2.0.0b3","2.0.0b4","2.0.0b5","2.0.0b6","2.0.0b7","2.1.0","2.10.0","2.11.0","2.12.0","2.13.0","2.14.0","2.14.1","2.15.0","2.16.0","2.17.0","2.18.0","2.19.0","2.2.0","2.20.0","2.21.0","2.22.0","2.23.0","2.24.0","2.25.0","2.26.0","2.27.0","2.27.1","2.28.0","2.29.0","2.3.0","2.30.0","2.31.0","2.31.1","2.32.0","2.32.1","2.32.2","2.33.0","2.34.0","2.35.0","2.35.1","2.35.3","2.36.0","2.37.0","2.38.0","2.39.0","2.4.0","2.40.0","2.41.0","2.42.0","2.43.0","2.5.0","2.5.1","2.6.0","2.7.0","2.8.0","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-vmxc-h2x2-jmf3/GHSA-vmxc-h2x2-jmf3.json"}},{"package":{"name":"pydantic-ai-slim","ecosystem":"PyPI","purl":"pkg:pypi/pydantic-ai-slim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.56.0"},{"fixed":"1.107.6"}]}],"versions":["1.100.0","1.101.0","1.102.0","1.103.0","1.104.0","1.105.0","1.106.0","1.107.0","1.107.1","1.107.2","1.107.4","1.107.5","1.56.0","1.57.0","1.58.0","1.59.0","1.60.0","1.61.0","1.62.0","1.63.0","1.64.0","1.65.0","1.66.0","1.67.0","1.68.0","1.69.0","1.70.0","1.71.0","1.72.0","1.73.0","1.74.0","1.75.0","1.76.0","1.77.0","1.78.0","1.79.0","1.80.0","1.81.0","1.82.0","1.83.0","1.84.0","1.84.1","1.85.0","1.85.1","1.86.0","1.86.1","1.87.0","1.88.0","1.89.0","1.89.1","1.90.0","1.91.0","1.92.0","1.93.0","1.94.0","1.95.0","1.95.1","1.96.0","1.96.1","1.97.0","1.98.0","1.99.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-vmxc-h2x2-jmf3/GHSA-vmxc-h2x2-jmf3.json"}},{"package":{"name":"pydantic-ai-slim","ecosystem":"PyPI","purl":"pkg:pypi/pydantic-ai-slim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0b1"},{"fixed":"2.44.0"}]}],"versions":["2.0.0","2.0.0b1","2.0.0b2","2.0.0b3","2.0.0b4","2.0.0b5","2.0.0b6","2.0.0b7","2.1.0","2.10.0","2.11.0","2.12.0","2.13.0","2.14.0","2.14.1","2.15.0","2.16.0","2.17.0","2.18.0","2.19.0","2.2.0","2.20.0","2.21.0","2.22.0","2.23.0","2.24.0","2.25.0","2.26.0","2.27.0","2.27.1","2.28.0","2.29.0","2.3.0","2.30.0","2.31.0","2.31.1","2.32.0","2.32.1","2.32.2","2.33.0","2.34.0","2.35.0","2.35.1","2.35.3","2.36.0","2.37.0","2.38.0","2.39.0","2.4.0","2.40.0","2.41.0","2.42.0","2.43.0","2.5.0","2.5.1","2.6.0","2.7.0","2.8.0","2.9.0","2.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-vmxc-h2x2-jmf3/GHSA-vmxc-h2x2-jmf3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}