GHSA-vmxc-h2x2-jmf3: SSRF

Published Oct 8, 2026
·
Updated

Summary

When an application using Pydantic AI opts a URL into local network access — either a FileUrl with forcedownload='allow-local', or webfetchtool(allowlocalurls=True) — the cloud-metadata blocklist could be bypassed by appending an IPv6 zone identifier to a metadata address (for example fd00:ec2::254%251). The host ignores the zone identifier on a destination that is not link-local and delivers the request to the metadata endpoint anyway, exposing cloud IAM short-term credentials.

This is an incomplete fix of GHSA-cqp8-fcvh-x7r3 / CVE-2026-46678 and GHSA-cg7w-rg45-pc59 / CVE-2026-48782, themselves follow-ups to CVE-2026-25580. The parent advisory's remediation guaranteed that cloud metadata endpoints are always blocked, even with local access allowed. That guarantee did not hold for zone-scoped spellings of the IPv6 metadata endpoints.

Details

The cloud-metadata guard compared IPv6 addresses against its blocklist by set membership. Python includes the zone identifier in IPv6Address equality and hashing, so a zone-scoped spelling of a blocked address did not match, while the network stack ignores the zone identifier for a destination that is not link-local. The private-range checks, and the IPv4 and transition-form metadata checks, were already unaffected, because they compare by network containment and by packed bytes respectively.

Only the IPv6 cloud metadata endpoints were reachable this way, so the issue requires an IPv6-enabled environment — for example AWS EC2 or EKS with IPv6, GCP IPv6-only instances, or Scaleway.

Who Is Affected

You are affected only if your application opts a URL that is, or could be, influenced by untrusted input into local network access, through either:

- a FileUrl (ImageUrl, AudioUrl, VideoUrl, DocumentUrl) with forcedownload='allow-local'; or - webfetchtool(allowlocalurls=True), where the model chooses the URL.

Both are off by default.

You are not affected through the FileUrl path if you use any of the bundled integrations to ingest user input, because they do not propagate forcedownload from external data:

- Agent.toweb / clai web - VercelAIAdapter - AGUIAdapter / Agent.toagui

webfetchtool is configured by your own application, so a client cannot turn on allowlocalurls.

Applications that only download from developer-controlled URLs are not affected.

Remediation

Upgrade to a patched version. The cloud-metadata and private-IP checks now drop an IPv6 zone identifier before evaluating the address, so every blocklist comparison is made on the address itself. A zone identifier is still carried on the connection, so legitimate link-local fetches under local network access continue to work.

Workaround for Unpatched Versions

Avoid opting into local network access — forcedownload='allow-local' or webfetchtool(allowlocalurls=True) — on any URL that could be influenced by untrusted input. If you must, reject URL hosts containing % before constructing the FileUrl or configuring the tool.

Credits

Reported by @euriconicacio.

Affected Software

4 affected componentsFixes available
pip/pydantic-ai-slim>=2.0.0b1<2.44.0
2.44.0
pip/pydantic-ai-slim>=1.56.0<1.107.6
1.107.6
pip/pydantic-ai>=2.0.0b1<2.44.0
2.44.0
pip/pydantic-ai>=1.56.0<1.107.6
1.107.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/pydantic-ai-slim to a version that resolves this vulnerability.

    Fixed in 2.44.0
  2. Upgrade

    Upgrade pip/pydantic-ai-slim to a version that resolves this vulnerability.

    Fixed in 1.107.6
  3. Upgrade

    Upgrade pip/pydantic-ai to a version that resolves this vulnerability.

    Fixed in 2.44.0
  4. Upgrade

    Upgrade pip/pydantic-ai to a version that resolves this vulnerability.

    Fixed in 1.107.6
  5. Configuration

    Do not opt URLs into local network access; keep web_fetch_tool(allow_local_urls=True) and FileUrl force_download='allow-local' disabled unless required.

    Pydantic AI web_fetch_tool and FileUrl allow_local_urls / force_download = allow_local_urls=False; force_download not set to 'allow-local'
  6. Compensating control

    If local network access is required, reject URL hosts containing '%' before constructing the FileUrl or configuring the web_fetch_tool.

Event History

Oct 8, 2026
Advisory Published
via GitHub·04:48 PM
Data Sourced
via GitHub·04:48 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed?

Exposure requires an application to explicitly permit local-network URL access through either FileUrl with force_download='allow-local' or web_fetch_tool(allow_local_urls=True). The issue is not described as affecting applications that do not enable either option.

2

What does an attacker need to trigger the bypass?

The request must use a cloud-metadata IPv6 address written with an appended IPv6 zone identifier, such as fd00:ec2::254%251. The host ignores that zone identifier for a non-link-local destination and can still send the request to the metadata endpoint.

3

What can be done if patching is not immediately possible?

Disable local URL access by removing force_download='allow-local' and setting allow_local_urls=False. This prevents the affected local-network access paths from being enabled.

4

What is exposed if the metadata request succeeds?

A successful request can expose cloud IAM short-term credentials obtained from the cloud metadata endpoint.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203