CVE-2026-25580Disclosure(pydantic / pydantic_ai)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pydantic pydantic_ai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When applications accept message history from untrusted sources, attackers can include malicious URLs that cause the server to make HTTP requests to internal network resources, potentially accessing internal services or cloud credentials. This vulnerability only affects applications that accept message history from external users. This vulnerability is fixed in 1.56.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pydantic_ai

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-06); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
pydantic_ai

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-06: 3Mentions · 2026-02-08: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-02-06: 3Technical Details · 2026-02-08: 102-0602-08
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-063
Disclosure2Patch1
2026-02-081
Disclosure1
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-25580 - High Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in P... https://www.thehackerwire.com/vulnerability/CVE-2026-25580/ https://t.co/ntiMN5M6bR

    Post summary

    The post announces a high‑severity SSRF vulnerability (CVE‑2026‑25580) in Pydantic AI, specifying affected versions but providing no PoC, exploit, or patch details.

    1000060
    113 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A Server-Side Request Forgery (SSRF) flaw (CVE-2026-25580) impacts Pydantic AI in its URL download handling. This could enable internal network reconnaissance. #PydanticAI #SSRF #infosec https://www.pulsepatch.io/posts/cve-2026-25580-pydantic-ai-ssrf

    Post summary

    A newly disclosed SSRF vulnerability (CVE-2026-25580) in Pydantic AI's URL download handling could enable internal network reconnaissance.

    0000068
    1 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25580: HIGH] Pydantic AI has fixed a Server-Side Request Forgery (SSRF) vulnerability in its URL download feature that could expose internal resources to attackers. Update to version 1.56.0 to stay...#cve,CVE-2026-25580,#cybersecurity https://cvefind.com/CVE-2026-25580

    Post summary

    Pydantic AI has patched a high‑severity SSRF vulnerability; users are advised to update to version 1.56.0.

    0000069
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25580 Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) … https://www.cve.org/CVERecord?id=CVE-2026-25580

    Post summary

    The entry announces CVE-2026-25580 as an SSRF flaw affecting Pydantic AI versions 0.0.26 through 1.55.x, with a reference to the official CVE record.

    00000175
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppydanticpydantic_ai-python-

Explore more