PatchSiren cyber security CVE debrief
CVE-2026-107288 pydantic CVE debrief
Pydantic AI's web_fetch_tool has a blocked_domains bypass vulnerability via a hostname that the resolver normalizes differently. This issue affects Pydantic AI versions from 1.77.0 until 1.107.6 and 2.44.0. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string, causing the application to fetch that host with its own privileges.
- Vendor
- pydantic
- Product
- pydantic-ai
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Pydantic AI deployments should assess exposure and prioritize updates to fixed versions. They should also review model inputs and restrict them to prevent attacker-influenced hostnames.
Why it matters
Defenders should care about this vulnerability because it allows an attacker-influenced model to bypass blocked_domains checks, potentially leading to unauthorized host access with application privileges. Affected versions need to be updated to 1.107.6 or 2.44.0, and model inputs should be reviewed and restricted to prevent this bypass.
- Potential unauthorized host access with application privileges
- Need to verify affected versions and update to fixed versions
- Requires review and restriction of model inputs to prevent attacker-influenced hostnames
- Monitoring for unusual web_fetch_tool activity is necessary
Technical summary
The vulnerability occurs because the local web_fetch_tool and WebFetch local fallback compare blocked_domains entries with a URL hostname before both values are normalized to the form used by getaddrinfo. An attacker-influenced model can use an equivalent IDNA spelling, non-ASCII label separator, case variation, or trailing root label that resolves to a blocked host but does not match the configured string.
Defensive priority
Defenders should prioritize verifying affected versions and updating to fixed versions 1.107.6 or 2.44.0. They should also review and restrict model inputs to prevent attacker-influenced hostnames.
Recommended defensive actions
- Verify if Pydantic AI versions 1.77.0 to 1.107.6 or 2.44.0 are in use and update to 1.107.6 or 2.44.0
- Review and restrict model inputs to prevent attacker-influenced hostnames
- Monitor for unusual web_fetch_tool activity
- Perform vulnerability scanning to identify potentially exposed systems
- Implement additional logging and monitoring for web_fetch_tool activity
- Review and update incident response plans to address potential exploitation
- Conduct a thorough risk assessment to identify potential attack vectors
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is limited information on potential exploitation or victim impact. Defenders should verify affected versions, review model inputs, and monitor for unusual activity. The vulnerability allows an attacker-influenced model to bypass blocked_domains checks, potentially leading to unauthorized host access with application privileges. Evidence is limited, and further verification is needed to assess exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107288 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107288
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107288 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107288
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Pydantic AI: web_fetch_tool blocked_domains bypass via a hostname the resolver normalizes differ
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107288.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-22h6-qm39-v87j
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/8407
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/8409
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/8421
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/490335f8e2322e143a79337ddca9410e0176c812
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/a9dab92099d0ef9d5d4aa34ccac8a6f1b0e51284
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/c1f212a084cbfa0012f2044cdb4731d214b3b983
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.