Server-side Request Forgery (SSRF) Affecting pydantic-ai-slim package, versions [1.56.0,1.99.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.42% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-PYDANTICAISLIM-16796278
  • published22 May 2026
  • disclosed21 May 2026
  • creditJ0hndo

Introduced: 21 May 2026

CVE-2026-46678  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade pydantic-ai-slim to version 1.99.0 or higher.

Overview

pydantic-ai-slim is an Agent Framework / shim to use Pydantic with LLMs, slim package

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via incomplete blocklist in is_private_ip function when force_download='allow-local' is enabled. An attacker can access sensitive cloud metadata information by submitting a specially crafted URL containing an IPv4-mapped IPv6, 6to4, or NAT64 encoded address that bypasses the intended blocklist. This is only exploitable if the application explicitly opts for FileUrl (ImageUrl, AudioUrl, VideoUrl, DocumentUrl) in force_download='allow-local' on a URL that is, or could be, influenced by untrusted input.

Note:

This issue is due to incomplete fix for CVE-2026-25580.

CVSS Base Scores

version 4.0
version 3.1