<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:11:31 +0000</lastBuildDate>
    <item>
      <title>BREW-oterm-CVE-2026-46678 — Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)</title>
      <link>https://cve.radiocsirt.org/vuln/brew-oterm-cve-2026-46678</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: oterm&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When an application using Pydantic AI opts a URL into `force_download=&amp;#39;allow-local&amp;#39;` (which disables the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form (IPv4-mapped IPv6, 6to4, or NAT64). Dual-stack and translated networks route the IPv6 wrapper to the underlying IPv4 endpoint, exposing cloud IAM short-term credentials.&lt;/p&gt;
&lt;p&gt;This is an incomplete fix of [GHSA-2jrp-274c-jhv3](https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-2jrp-274c-jhv3) / [CVE-2026-25580](https://nvd.nist.gov/vuln/detail/CVE-2026-25580). The parent advisory&amp;#39;s remediation guaranteed that &amp;#34;cloud metadata endpoints are always blocked, even with `allow-local`.&amp;#34; That guarantee did not hold for IPv6-encoded forms of the metadata IPs.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;Same impact metrics as the parent CVE, but materially narrower attack surface (AC:H instead of AC:L), because exploitation requires the application to have opted into `allow-local` on a URL influenced by untrusted input.&lt;/p&gt;
&lt;p&gt;## Who Is Affected&lt;/p&gt;
&lt;p&gt;Applications are affected **only if** they explicitly opt for `FileUrl` (`ImageUrl`, `AudioUrl`, `VideoUrl`, `DocumentUrl`) into `force_download=&amp;#39;allow-local&amp;#39;` on a URL that is, or could be, influenced by untrusted input.&lt;/p&gt;
&lt;p&gt;Applications are **not** affected if they use any of the bundled integrations to ingest user input, because they do not propagate `force_download` from external data:&lt;/p&gt;
&lt;p&gt;- `Agent.to_web` / `clai we…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: oterm&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When an application using Pydantic AI opts a URL into `force_download=&amp;#39;allow-local&amp;#39;` (which disables the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form (IPv4-mapped IPv6, 6to4, or NAT64). Dual-stack and translated networks route the IPv6 wrapper to the underlying IPv4 endpoint, exposing cloud IAM short-term credentials.&lt;/p&gt;
&lt;p&gt;This is an incomplete fix of [GHSA-2jrp-274c-jhv3](https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-2jrp-274c-jhv3) / [CVE-2026-25580](https://nvd.nist.gov/vuln/detail/CVE-2026-25580). The parent advisory&amp;#39;s remediation guaranteed that &amp;#34;cloud metadata endpoints are always blocked, even with `allow-local`.&amp;#34; That guarantee did not hold for IPv6-encoded forms of the metadata IPs.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;Same impact metrics as the parent CVE, but materially narrower attack surface (AC:H instead of AC:L), because exploitation requires the application to have opted into `allow-local` on a URL influenced by untrusted input.&lt;/p&gt;
&lt;p&gt;## Who Is Affected&lt;/p&gt;
&lt;p&gt;Applications are affected **only if** they explicitly opt for `FileUrl` (`ImageUrl`, `AudioUrl`, `VideoUrl`, `DocumentUrl`) into `force_download=&amp;#39;allow-local&amp;#39;` on a URL that is, or could be, influenced by untrusted input.&lt;/p&gt;
&lt;p&gt;Applications are **not** affected if they use any of the bundled integrations to ingest user input, because they do not propagate `force_download` from external data:&lt;/p&gt;
&lt;p&gt;- `Agent.to_web` / `clai we…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-oterm-cve-2026-46678</guid>
    </item>
    <item>
      <title>CVE-2026-46678 — Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-46678</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; pydantic-ai, pydantic-ai-slim&lt;/p&gt;
&lt;p&gt;Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download=&amp;#39;allow-local&amp;#39; (disabling the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form (IPv4-mapped IPv6, 6to4, or NAT64), exposing cloud IAM short-term credentials on dual-stack or translated networks. This is an incomplete fix of GHSA-2jrp-274c-jhv3 / CVE-2026-25580, whose remediation did not hold for IPv6-encoded forms of the metadata IPs. An application is affected only if it explicitly opts a FileUrl (ImageUrl, AudioUrl, VideoUrl, DocumentUrl) into force_download=&amp;#39;allow-local&amp;#39; on a URL influenced by untrusted input; it is not affected when using bundled integrations to ingest user input (Agent.to_web / clai web, VercelAIAdapter, AGUIAdapter / Agent.to_ag_ui), since they do not propagate force_download from external data, nor when downloading only from developer-controlled URLs. This issue has been fixed in version 1.99.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; pydantic-ai, pydantic-ai-slim&lt;/p&gt;
&lt;p&gt;Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download=&amp;#39;allow-local&amp;#39; (disabling the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form (IPv4-mapped IPv6, 6to4, or NAT64), exposing cloud IAM short-term credentials on dual-stack or translated networks. This is an incomplete fix of GHSA-2jrp-274c-jhv3 / CVE-2026-25580, whose remediation did not hold for IPv6-encoded forms of the metadata IPs. An application is affected only if it explicitly opts a FileUrl (ImageUrl, AudioUrl, VideoUrl, DocumentUrl) into force_download=&amp;#39;allow-local&amp;#39; on a URL influenced by untrusted input; it is not affected when using bundled integrations to ingest user input (Agent.to_web / clai web, VercelAIAdapter, AGUIAdapter / Agent.to_ag_ui), since they do not propagate force_download from external data, nor when downloading only from developer-controlled URLs. This issue has been fixed in version 1.99.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-46678</guid>
    </item>
    <item>
      <title>GHSA-cqp8-fcvh-x7r3 — Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cqp8-fcvh-x7r3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pydantic-ai, PyPI: pydantic-ai-slim&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When an application using Pydantic AI opts a URL into `force_download=&amp;#39;allow-local&amp;#39;` (which disables the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form (IPv4-mapped IPv6, 6to4, or NAT64). Dual-stack and translated networks route the IPv6 wrapper to the underlying IPv4 endpoint, exposing cloud IAM short-term credentials.&lt;/p&gt;
&lt;p&gt;This is an incomplete fix of [GHSA-2jrp-274c-jhv3](https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-2jrp-274c-jhv3) / [CVE-2026-25580](https://nvd.nist.gov/vuln/detail/CVE-2026-25580). The parent advisory&amp;#39;s remediation guaranteed that &amp;#34;cloud metadata endpoints are always blocked, even with `allow-local`.&amp;#34; That guarantee did not hold for IPv6-encoded forms of the metadata IPs.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;Same impact metrics as the parent CVE, but materially narrower attack surface (AC:H instead of AC:L), because exploitation requires the application to have opted into `allow-local` on a URL influenced by untrusted input.&lt;/p&gt;
&lt;p&gt;## Who Is Affected&lt;/p&gt;
&lt;p&gt;Applications are affected **only if** they explicitly opt for `FileUrl` (`ImageUrl`, `AudioUrl`, `VideoUrl`, `DocumentUrl`) into `force_download=&amp;#39;allow-local&amp;#39;` on a URL that is, or could be, influenced by untrusted input.&lt;/p&gt;
&lt;p&gt;Applications are **not** affected if they use any of the bundled integrations to ingest user input, because they do not propagate `force_download` from external data:&lt;/p&gt;
&lt;p&gt;- `Agent.to_web` / `clai we…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pydantic-ai, PyPI: pydantic-ai-slim&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When an application using Pydantic AI opts a URL into `force_download=&amp;#39;allow-local&amp;#39;` (which disables the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form (IPv4-mapped IPv6, 6to4, or NAT64). Dual-stack and translated networks route the IPv6 wrapper to the underlying IPv4 endpoint, exposing cloud IAM short-term credentials.&lt;/p&gt;
&lt;p&gt;This is an incomplete fix of [GHSA-2jrp-274c-jhv3](https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-2jrp-274c-jhv3) / [CVE-2026-25580](https://nvd.nist.gov/vuln/detail/CVE-2026-25580). The parent advisory&amp;#39;s remediation guaranteed that &amp;#34;cloud metadata endpoints are always blocked, even with `allow-local`.&amp;#34; That guarantee did not hold for IPv6-encoded forms of the metadata IPs.&lt;/p&gt;
&lt;p&gt;## Severity&lt;/p&gt;
&lt;p&gt;Same impact metrics as the parent CVE, but materially narrower attack surface (AC:H instead of AC:L), because exploitation requires the application to have opted into `allow-local` on a URL influenced by untrusted input.&lt;/p&gt;
&lt;p&gt;## Who Is Affected&lt;/p&gt;
&lt;p&gt;Applications are affected **only if** they explicitly opt for `FileUrl` (`ImageUrl`, `AudioUrl`, `VideoUrl`, `DocumentUrl`) into `force_download=&amp;#39;allow-local&amp;#39;` on a URL that is, or could be, influenced by untrusted input.&lt;/p&gt;
&lt;p&gt;Applications are **not** affected if they use any of the bundled integrations to ingest user input, because they do not propagate `force_download` from external data:&lt;/p&gt;
&lt;p&gt;- `Agent.to_web` / `clai we…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cqp8-fcvh-x7r3</guid>
    </item>
  </channel>
</rss>
