Qeravio
Canonical AI event

Four security issues in web_fetch_tool and OpenTelemetry instrumentation are fixed in v2.44.0.

Security update v2.44.0 addresses four vulnerabilities in web_fetch_tool and OpenTelemetry instrumentation. Two issues were reported by @BrianWillows.

17 Sept 20261 verified claims1 sources1 observations
What happened

The official source reports this update: v2.44.0 (2026-09-16). 🛡️ Security This release fixes four security issues, all of them reached through web_fetch_tool or OpenTelemetry instrumentation. See each advisory for full details and affected versions. GHSA-vmxc-h2x2-jmf3 (moderate): the cloud-metadata and private-IP blocklists could be bypassed with an IPv6 zone identifier on a URL opted into local network access, via FileUrl(force_download='allow-local') or web_fetch_tool(allow_local_urls=True) . Both are off by default. Reported by @euriconicacio .

Why it matters

This official update documents a development concerning v2.44.0 (2026-09-16). Its practical significance depends on the scope and evidence stated by the source.

What to watch next

Read the official source update and verify its stated scope, evidence and timing before acting on it.

Connected knowledge

Entities affected by this event

Continue this topic
Evidence trail

Sources behind the event