Pydantic AI, Server-Side Request Forgery, CVE-2026-48782 (Medium) -DC-Oct2026-2927

Listen to this Post

When an application using Pydantic AI opts a URL into local network access—either via FileUrl with force_download=’allow-local’ or web_fetch_tool(allow_local_urls=True)—the cloud-metadata blocklist can be bypassed. This occurs because the cloud-metadata guard compares IPv6 addresses against its blocklist using strict set membership. Python includes the zone identifier in IPv6Address equality and hashing, meaning a zone-scoped spelling such as fd00:ec2::254%251 fails to match the blocked address. However, the underlying network stack ignores the zone identifier on destinations that are not link-local and successfully delivers the request to the cloud metadata endpoint. This flaw represents an incomplete fix for prior advisories (GHSA-cqp8-fcvh-x7r3 / CVE-2026-46678). Because the guard fails to strip the zone identifier before performing blocklist evaluations, attackers can exploit IPv6-enabled cloud environments (such as AWS EC2/EKS with IPv6, GCP IPv6-only instances, or Scaleway) to bypass security controls. Successful exploitation forces the application to fetch metadata resources, potentially exposing sensitive cloud IAM short-term credentials to unauthorized actors.

DailyCVE Form:

Platform: Pydantic AI
Version: 1.56.0-1.101.0
Vulnerability : SSRF
Severity: Medium
date: 2026-06-17

Prediction: June 2026

What Undercode Say:

The vulnerability stems from a logical discrepancy between how Python handles equality and hashing for `IPv6Address` objects containing zone identifiers versus how the underlying operating system network stack routes non-link-local packets. Because security guards implemented strict set membership checks without normalizing the input strings or stripping trailing scope IDs, an attacker could easily manipulate formatting characters. Security audits of agentic frameworks should closely inspect network boundary checks, ensuring that URL parsing and IP comparison routines strip trailing suffixes and handle transition forms uniformly across all supported address families.

Analytics:

Target components: Pydantic AI `FileUrl` and `web_fetch_tool`

Vector type: Network (IPv6)

Impact metric: High Confidentiality (Cloud IAM Credentials)

Bash:

pip install --upgrade pydantic-ai
python -c "import pydantic_ai; print(pydantic_ai.<strong>version</strong>)"

Exploit: (Educational Purposes!)

from pydantic_ai.tools import web_fetch_tool
Conceptual PoC demonstrating zone-scoped IPv6 metadata bypass vector
malicious_url = "http://[fd00:ec2::254%251]/latest/meta-data/iam/security-credentials/"
If local network access is permitted via allow_local_urls=True,
the guard blocklist comparison fails, permitting access to metadata endpoints.

Protection: from this CVE

Upgrade Pydantic AI to version 1.102.0 or higher (or 2.0.0b3+) where IPv6 zone identifiers are systematically stripped before blocklist evaluation.
Avoid enabling local network access flags (force_download='allow-local' or allow_local_urls=True) on paths influenced by untrusted user input.
Implement strict validation to reject URL hosts containing percentage signs (%) prior to constructing file objects or tool configurations.

Impact:

Successful exploitation allows unauthorized retrieval of cloud instance metadata, leading directly to the exposure of short-term cloud IAM credentials and potential compromise of the host infrastructure.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top