{"data":{"id":"dc3ad503-128f-4c24-bbbb-0543e3a2412c","title":"GHSA-cg7w-rg45-pc59: pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)","summary":"Pydantic AI versions 1.56.0 up to 1.102.0 (and 2.0.0b1 up to 2.0.0b3) contain an incomplete fix for CVE-2026-46678, an SSRF blocklist bypass. When an application sets force_download='allow-local' on a URL that untrusted input can influence, the cloud-metadata blocklist can be evaded by encoding the metadata IP in IPv6 transition forms the previous fix did not decode, exposing cloud IAM short-term credentials. Exploitation requires NAT64- or ISATAP-routing networks, and the advisory rates it MEDIUM (CVSS 6.8).","solution":"Upgrade to 1.102.0 or later, or 2.0.0b3 or later on the 2.0 pre-release line. The cloud-metadata and private-IP blocklists now decode the embedded IPv4 of every standardized IPv6 transition form before evaluating it, including IPv4-mapped, IPv4-compatible, 6to4, and NAT64 across all prefix lengths.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-cg7w-rg45-pc59","publishedAt":"2026-06-26T19:17:56.000Z","cveId":"CVE-2026-48782","cweIds":["CWE-918"],"cvssScore":"6.8","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["pydantic-ai-slim@>= 1.56.0, < 1.102.0 (fixed: 1.102.0)","pydantic-ai@>= 1.56.0, < 1.102.0 (fixed: 1.102.0)","pydantic-ai@>= 2.0.0b1, < 2.0.0b3 (fixed: 2.0.0b3)","pydantic-ai-slim@>= 2.0.0b1, < 2.0.0b3 (fixed: 2.0.0b3)"],"affectedPackageNames":["pydantic-ai-slim","pydantic-ai"],"affectedPackageRefs":["pypi:pydantic-ai-slim","pypi:pydantic-ai"],"affectedVendors":[],"affectedVendorsRaw":["pydantic-ai","pydantic-ai-slim"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00417,"epssCheckedAt":"2026-10-10T04:57:24.600Z","kevDateAdded":null,"advisoryAliases":["GHSA-cg7w-rg45-pc59"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-06-26T19:17:56.000Z","capecIds":["CAPEC-664"],"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}