CVE-2026-107288: Pydantic AI: web_fetch_tool blocked_domains bypass via a hostname the resolver normalizes differently
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local webfetchtool and the WebFetch local fallback compare blockeddomains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. alloweddomains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pydantic AIto a version that resolves this vulnerability.Fixed in 1.107.6 - Upgrade
Upgrade
Pydantic AIto a version that resolves this vulnerability.Fixed in 2.44.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using the local web_fetch_tool or the WebFetch local fallback are affected when they rely on blocked_domains entries. The affected versions are from 1.77.0 until the fixes in 1.107.6 and 2.44.0.
What does an attacker need to exploit this issue?
An attacker needs to influence the model so it requests a hostname spelling that resolves to a blocked host but does not exactly match the configured blocked_domains string. Relevant variations include equivalent IDNA spellings, non-ASCII label separators, case changes, and a trailing root label.
What can be done before upgrading?
Use allowed_domains rather than relying only on blocked_domains where feasible, because unmatched hostname spellings fail closed with an allowlist. Private-IP and cloud-metadata protections remain effective.
What is the permanent remediation?
Upgrade to Pydantic AI version 1.107.6 or 2.44.0, which normalize hostnames before comparing them to blocked domain entries.