Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
Modified: 7/13/2026
package
pkg:pypi/pydantic-ai
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
Modified: 7/13/2026
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
Modified: 7/13/2026
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
Modified: 7/13/2026
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Modified: 8/19/2026
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL
Modified: 7/13/2026
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
Modified: 7/13/2026
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
Modified: 7/13/2026
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
Modified: 7/13/2026
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL
Modified: 7/13/2026
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Modified: 8/19/2026