Pydantic AI cloud-metadata blocklist bypass via IPv6 transition addresses (CVE-2026-48782)
Pydantic AI versions 1.56.0 through 1.101.0 and 2.0.0 betas allowed its cloud-metadata IP blocklist to be bypassed by encoding the metadata IP in IPv6 transition forms (IPv4-compatible IPv6, NAT64 local-use and operator prefixes, ISATAP) that the earlier fix for CVE-2026-46678 did not decode, potentially exposing cloud IAM short-term credentials. Exploitation requires an application to opt a URL into force_download='allow-local' and to run on a network routing the affected transition forms; the issue was fixed in version 2.0.0b3.
Disclosed 17 June 2026 · Record updated 13 September 2026
Impact
Bypass of the internal/metadata IP block could let a fetched URL reach the cloud metadata endpoint and expose cloud IAM short-term credentials on NAT64- or ISATAP-routed networks.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48782
