Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. allowed_domains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.

Project Subscriptions

Vendors Products
Pydantic Subscribe
Pydantic-ai Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Pydantic
Pydantic pydantic-ai
Vendors & Products Pydantic
Pydantic pydantic-ai

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges. allowed_domains fails closed for unmatched spellings, and private-IP and cloud-metadata protections remain effective. This issue is fixed in versions 1.107.6 and 2.44.0.
Title Pydantic AI: web_fetch_tool blocked_domains bypass via a hostname the resolver normalizes differently
Weaknesses CWE-1289
CWE-918
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:28:53.801Z

Reserved: 2026-10-07T15:53:23.586Z

Link: CVE-2026-107288

cve-icon Vulnrichment

Updated: 2026-10-08T17:28:33.935Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T16:17:04.147

Modified: 2026-10-08T20:35:31.200

Link: CVE-2026-107288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:45:17Z

Weaknesses