PT-2026-108054 · Unknown · Pydantic-Ai
CVE-2026-107294
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Pydantic AI versions 1.77.0 through 1.107.1
Pydantic AI versions prior to 2.24.0
Description
Certain remote-content download paths buffer the entire HTTP response body into memory before enforcing content-size controls. This occurs when using the
web fetch tool, the WebFetch local fallback, and remote FileUrl media downloads, including ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. An attacker can provide a URL that streams an arbitrarily large response, leading to process memory exhaustion and worker crashes. This is an availability issue; Server-Side Request Forgery (SSRF) protections remain effective, and there is no impact on confidentiality or integrity.Recommendations
Update Pydantic AI to version 1.107.2 or later.
Update Pydantic AI to version 2.24.0 or later.
Fix
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pydantic-Ai