Skip to content
MediumVulnerability

GHSA-cg7w-rg45-pc59: pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)

Published
Record updated
View JSON
Affected
  • pydantic-ai-slim >= 1.56.0, < 1.102.0, fixed in 1.102.0
  • pydantic-ai >= 1.56.0, < 1.102.0, fixed in 1.102.0
  • pydantic-ai >= 2.0.0b1, < 2.0.0b3, fixed in 2.0.0b3
  • and 1 more
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

Pydantic AI versions 1.56.0 up to 1.102.0 (and 2.0.0b1 up to 2.0.0b3) contain an incomplete fix for CVE-2026-46678, an SSRF blocklist bypass. When an application sets force_download='allow-local' on a URL that untrusted input can influence, the cloud-metadata blocklist can be evaded by encoding the metadata IP in IPv6 transition forms the previous fix did not decode, exposing cloud IAM short-term credentials. Exploitation requires NAT64- or ISATAP-routing networks, and the advisory rates it MEDIUM (CVSS 6.8).

Mitigation

Upgrade to 1.102.0 or later, or 2.0.0b3 or later on the 2.0 pre-release line. The cloud-metadata and private-IP blocklists now decode the embedded IPv4 of every standardized IPv6 transition form before evaluating it, including IPv4-mapped, IPv4-compatible, 6to4, and NAT64 across all prefix lengths.