PT-2026-108054 · Unknown · Pydantic-Ai

CVE-2026-107294

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pydantic AI versions 1.77.0 through 1.107.1 Pydantic AI versions prior to 2.24.0
Description Certain remote-content download paths buffer the entire HTTP response body into memory before enforcing content-size controls. This occurs when using the web fetch tool, the WebFetch local fallback, and remote FileUrl media downloads, including ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. An attacker can provide a URL that streams an arbitrarily large response, leading to process memory exhaustion and worker crashes. This is an availability issue; Server-Side Request Forgery (SSRF) protections remain effective, and there is no impact on confidentiality or integrity.
Recommendations Update Pydantic AI to version 1.107.2 or later. Update Pydantic AI to version 2.24.0 or later.

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107294
GHSA-V2XH-2VP8-57H8

Affected Products

Pydantic-Ai