CVE-2026-107288: Pydantic AI: web_fetch_tool blocked_domains bypass via a hostname the resolver normalizes differently

Published Oct 8, 2026
·
Updated

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local webfetchtool and the WebFetch local fallback compare blockeddomains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. alloweddomains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.

Affected Software

1 affected component
pypi/pydantic-ai>=1.77.0<1.107.6, >=2.0.0<2.44.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Pydantic AI to a version that resolves this vulnerability.

    Fixed in 1.107.6
  2. Upgrade

    Upgrade Pydantic AI to a version that resolves this vulnerability.

    Fixed in 2.44.0

Event History

Oct 8, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using the local web_fetch_tool or the WebFetch local fallback are affected when they rely on blocked_domains entries. The affected versions are from 1.77.0 until the fixes in 1.107.6 and 2.44.0.

2

What does an attacker need to exploit this issue?

An attacker needs to influence the model so it requests a hostname spelling that resolves to a blocked host but does not exactly match the configured blocked_domains string. Relevant variations include equivalent IDNA spellings, non-ASCII label separators, case changes, and a trailing root label.

3

What can be done before upgrading?

Use allowed_domains rather than relying only on blocked_domains where feasible, because unmatched hostname spellings fail closed with an allowlist. Private-IP and cloud-metadata protections remain effective.

4

What is the permanent remediation?

Upgrade to Pydantic AI version 1.107.6 or 2.44.0, which normalize hostnames before comparing them to blocked domain entries.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203