漏洞描述翻译: Pydantic AI 是一个用于构建生成式 AI 应用和工作流的 Python 智能体框架。在版本 1.77.0 至 1.107.6 以及 2.44.0 之前, 和 WebFetch 的本地回退机制在将 条目与 URL 主机名进行比较时,未先将两者统一转换为 所使用的标准化格式。攻击者可利用模型可控的等效 IDNA 拼写、非 ASCII 标签分隔符、大小写差异或尾部根标签等方式,使解析结果指向一个被阻止的主机,但该主机名称在比较时无法与配置中的字符串匹配,从而导致应用以自身权限访问该主机。 对于不
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pydantic | pydantic-ai | >= 1.77.0, < 1.107.6 | - |
|
| pydantic | pydantic-ai-slim | >= 1.77.0, < 1.107.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107295 | 7.6 HIGH | `pydantic-ai-slim` web UI `/api/chat` accepts browser-simple cross-origin requests that ca |
| CVE-2026-107286 | 7.5 HIGH | Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends e |
| CVE-2026-107289 | 6.8 MEDIUM | Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifier (incomplete fix |
| CVE-2026-107287 | 6.5 MEDIUM | Pydantic AI: Excessive resource use when local web fetching converts nested HTML |
| CVE-2026-107290 | 6.5 MEDIUM | Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch` |
| CVE-2026-107294 | 6.5 MEDIUM | Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl |
| CVE-2026-107292 | 6.4 MEDIUM | Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not v |
| CVE-2026-107291 | 2.3 LOW | Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans in |
| CVE-2026-107293 | 2.3 LOW | Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `incl |
No comments yet