<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:58:28.700792+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-25580</id>
    <title>CVE-2026-25580 — Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handling</title>
    <updated>2026-10-03T06:58:28.702518+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> pydantic-ai, Red Hat Enterprise Linux AI (RHEL AI) 3</p>
<p>Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When applications accept message history from untrusted sources, attackers can include malicious URLs that cause the server to make HTTP requests to internal network resources, potentially accessing internal services or cloud credentials. This vulnerability only affects applications that accept message history from external users. This vulnerability is fixed in 1.56.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-25580"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2jrp-274c-jhv3</id>
    <title>GHSA-2jrp-274c-jhv3 — Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling</title>
    <updated>2026-10-03T06:58:28.702576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pydantic-ai, PyPI: pydantic-ai-slim</p>
<p>## Summary</p>
<p>A Server-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When applications accept message history from untrusted sources, attackers can include malicious URLs that cause the server to make HTTP requests to internal network resources, potentially accessing internal services or cloud credentials.</p>
<p>**This vulnerability only affects applications that accept message history from external users**, such as those using:
- **`Agent.to_web`** or **`clai web`** to serve a chat interface
- **`VercelAIAdapter`** for Vercel AI SDK integration
- **`AGUIAdapter`** or **`Agent.to_ag_ui`** for AG-UI protocol integration
- Custom APIs that accept message history from user input</p>
<p>Applications that only use hardcoded or developer-controlled URLs are not affected.</p>
<p>### Description</p>
<p>The `download_item()` helper function downloads content from URLs without validating that the target is a public internet address. When user-supplied message history contains URLs, attackers can:</p>
<p>1. **Access internal services**: Request `http://127.0.0.1`, `localhost`, or private IP ranges (`10.x.x.x`, `172.16.x.x`, `192.168.x.x`)
2. **Steal cloud credentials**: Access cloud metadata endpoints (AWS IMDSv1 at `169.254.169.254`, GCP, Azure, Alibaba Cloud)
3. **Scan internal networks**: Enumerate internal hosts and ports</p>
<p>### Who Is Affected</p>
<p>You are affected if your application:</p>
<p>1. **Uses `Agent.to_web` or `clai web`** - The web interface accepts file attachment…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2jrp-274c-jhv3"/>
  </entry>
</feed>
