Recently added

svg-sanitizer: Mixed-case xlink:HrEf skips the `<use>` nesting-DoS check in Resolver::processReferences

Resolver::processReferences() collects <use> elements with the XPath predicate use[@href or @xlink:href], which is case sensitive. A <use> element written as xlink:HrEf is therefore never added to the reference graph, so the nesting-DoS nullification never marks it for removal. Sanitizer::cleanHrefAttributes() then runs later in the same pass and rewrites xlink:HrEf back to the canonical xlink:href. The sanitizer hands back a fully live nesting bomb that it would have stripped completely had …

Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl

Several remote-content download paths in Pydantic AI buffered the entire HTTP response body into memory before enforcing any size limit. An application that exposes the local web-fetch tool (web_fetch_tool, or the WebFetch capability's local fallback) to untrusted prompts can be driven to fetch an attacker-chosen URL that streams a very large body, exhausting process memory and crashing the worker. The same unbounded buffering applied to FileUrl media downloads (ImageUrl, DocumentUrl, …

Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl

Several remote-content download paths in Pydantic AI buffered the entire HTTP response body into memory before enforcing any size limit. An application that exposes the local web-fetch tool (web_fetch_tool, or the WebFetch capability's local fallback) to untrusted prompts can be driven to fetch an attacker-chosen URL that streams a very large body, exhausting process memory and crashing the worker. The same unbounded buffering applied to FileUrl media downloads (ImageUrl, DocumentUrl, …

Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers

When an application using Pydantic AI opts a URL into local network access — either a FileUrl with force_download='allow-local', or web_fetch_tool(allow_local_urls=True) — the cloud-metadata blocklist could be bypassed by appending an IPv6 zone identifier to a metadata address (for example fd00:ec2::254%251). The host ignores the zone identifier on a destination that is not link-local and delivers the request to the metadata endpoint anyway, exposing cloud IAM short-term credentials.

Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers

When an application using Pydantic AI opts a URL into local network access — either a FileUrl with force_download='allow-local', or web_fetch_tool(allow_local_urls=True) — the cloud-metadata blocklist could be bypassed by appending an IPv6 zone identifier to a metadata address (for example fd00:ec2::254%251). The host ignores the zone identifier on a destination that is not link-local and delivers the request to the metadata endpoint anyway, exposing cloud IAM short-term credentials.

Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`

The local web-fetch tool (web_fetch_tool, also used as the WebFetch capability's local fallback) processed responses with several steps whose running time grows quadratically with the size of certain server-controlled inputs, and ran them on the event loop: decoding the body with whichever charset the server declared, extracting the page title with a backtracking regular expression, and converting the HTML to markdown. An application that exposes this tool to untrusted prompts …

Recently updated

Two LiteLLM versions published containing credential harvesting malware

After an API Token exposure from an exploited trivy dependency, two new releases of litellm were uploaded to PyPI containing automatically activated malware, harvesting sensitive credentials and files, and exfiltrating to a remote API. Anyone who has installed and run the project should assume any credentials available to litellm environment may have been exposed, and revoke/rotate thema ccordingly.