Junglewise Threat Intelligence

CVE-2026-25580: Pydantic Pydantic AI SSRF in URL download functionality

CVE-2026-25580 · Severity: high · CVSS 8.6 · Published 2026-02-06

Technologies: Red Hat Enterprise Linux AI (RHEL AI) 3, pydantic-ai (PyPI), pydantic-ai-slim (PyPI), Pydantic AI Slim, PydanticAI. Vendors: Red Hat, PyPI, Pydantic.

Executive brief

Pydantic AI is a framework used to build applications powered by Generative AI. A security flaw in how the framework handles web links (URLs) allows attackers to trick the server into making unauthorized requests to internal systems. This could lead to the exposure of sensitive internal data, such as cloud service credentials or private network information, if the application accepts chat history or file attachments from external users.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the `download_item()` helper function within Pydantic AI. The component fails to validate that user-supplied URLs in message history (such as ImageUrl, AudioUrl, or VideoUrl objects) point to public internet addresses. An unauthenticated remote attacker can provide URLs targeting internal IP ranges (e.g., 127.0.0.1, 10.x.x.x) or cloud metadata services (e.g., 169.254.169.254) to exfiltrate sensitive credentials or scan internal networks. The fix, introduced in version 1.56.0, implements a new `_ssrf.py` module that enforces protocol validation, performs DNS resolution before requests to prevent rebinding, and blocks private/link-local IP ranges by default.

Affected products

  • pydantic pydantic-ai >= 0.0.26, < 1.56.0
  • pydantic pydantic-ai-slim >= 0.0.26, < 1.56.0
  • Red Hat Red Hat Enterprise Linux AI (RHEL AI) 3 3

Timeline

  • 2026-02-05: patched: Fix committed to repository
  • 2026-02-06: advisory: GitHub Security Advisory published
  • 2026-02-06: disclosed: CVE-2026-25580 published

References

Related threats