CVE-2026-107292 | Pydantic AI up to 2.0.0b0/2.29.x Host Header Validation Agent.to_web dns rebinding

SecurityVulns

A vulnerability marked as critical has been reported in Pydantic AI up to 2.0.0b0/2.29.x. Impacted is the function Agent.to_web of the component Host Header Validation. The manipulation of the argument Host leads to reliance on reverse dns resolution.

This vulnerability is referenced as CVE-2026-107292. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More