Vulnerability in Pydantic AI Python Framework Allows Bypass of Cloud Metadata Blocklist
CVE-2026-46678
What is CVE-2026-46678?
A vulnerability in the Pydantic AI framework allows applications to reconfigure their URL settings to bypass the cloud-metadata blocklist when 'force_download' is set to 'allow-local'. This occurs when an application opts for URLs influenced by untrusted input. The flawed mechanism permits encoding of private or internal IPs in an IPv6 transition format, exposing sensitive cloud IAM short-term credentials in dual-stack networks. This issue is a continuation of previous vulnerabilities where the fix was incomplete for specific encoded metadata IP forms. The vulnerability affects all versions from 1.56.0 to 1.98.0, with the patch implemented in version 1.99.0, reinforcing the necessity for users to upgrade to safeguard sensitive information.
Affected Version(s)
pydantic-ai >= 1.56.0, < 1.99.0
pydantic-ai-slim >= 1.56.0, < 1.99.0
