Bypass of Cloud Metadata Blocklist in Pydantic AI by Encoding Metadata IP
CVE-2026-48782

6.8MEDIUM

Key Information:

Vendor

Pydantic

Vendor
CVE Published:
16 June 2026

What is CVE-2026-48782?

The vulnerability in Pydantic AI allows attackers to bypass the cloud-metadata blocklist through specific IPv6 transition forms. Versions 1.56.0 to 1.101.0 and 2.0.0b1 to 2.0.0b2 are affected, potentially exposing sensitive cloud IAM short-term credentials. This issue arises when applications utilizing Pydantic AI opt to disable the default protections against private or internal IP addresses. Networks routing the affected IPv6 transition forms are particularly at risk. This vulnerability highlights the inadequacy of prior fixes and the importance of comprehensive remediation strategies.

Affected Version(s)

pydantic-ai >= 1.56.0, < 1.102.0 < 1.56.0, 1.102.0

pydantic-ai >= 2.0.0b1, < 2.0.0b3 < 2.0.0b1, 2.0.0b3

pydantic-ai-slim >= 2.0.0b1, < 2.0.0b3 < 2.0.0b1, 2.0.0b3

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.