Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. allowed_domains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.
Published: 2026-10-08
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: Unintended HTTP requests to blocked domains, potentially exposing data accessed by the application.
Action: Apply Patch
AI Analysis

Impact

The vulnerability in Pydantic AI's web_fetch_tool allows a malicious or trainer‑influenced prompt to be crafted with an alternate IDNA spelling, non‑ASCII separator, or case variation that normalises to a blocked hostname. When the local web_fetch_tool compares the configured blocked_domains list it performs the match before either string is fully normalised, enabling the request to proceed to the unintended host. This can result in the application fetching data from any host that matches after normalization, creating potential data leakage or side‑channel exposure.

Affected Systems

This issue affects the Pydantic AI Python agent framework (pydantic:pydantic-ai and pydantic:pydantic-ai-slim) in releases from 1.77.0 through 1.107.5 and in 2.44.0 prior to the 2.44.0 patch. Versions 1.107.6 and 2.44.0 contain the fix. Any deployment that employs the local web_fetch_tool or its fallback is subject to this flaw.

Risk and Exploitability

The CVSS score of 3.7 reflects a low‑severity flaw that requires an attacker‑influenced AI model to supply a crafted hostname, so it is not a high‑profile remote code execution risk. EPSS is currently unavailable, and the vulnerability has not been listed in the CISA KEV catalog, suggesting limited exploitation activity to date. Nevertheless, since the flaw can be triggered by model prompts, operators should be aware that an attacker who can influence model behaviour may cause the application to make unexpected outbound requests, potentially exposing private data or violating network policies. The path of exploitation involves supplying a specially encoded domain in the model prompt that resolves to a blocked host after normalisation, bypassing the blocked_domains filter.

Generated by OpenCVE AI on October 8, 2026 at 17:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Pydantic AI to v1.107.6 or a newer v2.44.0 release, where the normalization validation is corrected.
  • If an upgrade is not feasible, disable the web_fetch_tool or replace it with an implementation that normalises domains before applying the blocked_domains check.
  • Configure the application to log all outbound HTTP requests and review logs for requests that target hosts that were previously blocked, enabling early detection of bypass attempts.

Generated by OpenCVE AI on October 8, 2026 at 17:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Pydantic
Pydantic pydantic-ai
Vendors & Products Pydantic
Pydantic pydantic-ai

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. allowed_domains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.
Title Pydantic AI: web_fetch_tool blocked_domains bypass via a hostname the resolver normalizes differently
Weaknesses CWE-1289
CWE-918
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Pydantic Pydantic-ai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:28:53.801Z

Reserved: 2026-10-07T15:53:23.586Z

Link: CVE-2026-107288

cve-icon Vulnrichment

Updated: 2026-10-08T17:28:33.935Z

cve-icon NVD

Status : Received

Published: 2026-10-08T16:17:04.147

Modified: 2026-10-08T18:17:16.727

Link: CVE-2026-107288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:45:17Z

Weaknesses
  • CWE-1289

    Improper Validation of Unsafe Equivalence in Input

  • CWE-918

    Server-Side Request Forgery (SSRF)