CVE-2026-107290: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`
The local web-fetch tool (web_fetch_tool, also used as the WebFetch capability’s local fallback) processed responses with several steps whose running time grows quadratically with the size of certain server-controlled inputs, and ran them on the event loop: decoding the body with whichever charset the server declared, extracting the page title with a backtracking regular expression, and converting the HTML to markdown. An application that exposes this tool to untrusted prompts can be steered to fetch an attacker-controlled page of a megabyte or two that blocks the event loop for minutes, stalling every other coroutine in the process — other agent runs, other requests being served — for the duration.
This is an availability issue only. SSRF protections and the download size limit introduced in GHSA-v2xh-2vp8-57h8 are unaffected; that limit bounds how much is downloaded, not how long the response takes to process.
References
- github.com/advisories/GHSA-fpf4-vwcp-v4hp
- github.com/pydantic/pydantic-ai/commit/2faa6181d8a17d83bc9516d035c5270db8730fa0
- github.com/pydantic/pydantic-ai/commit/9cdc952e4c3319e85a3e04f2de49fbbb765bd38b
- github.com/pydantic/pydantic-ai/commit/a93ea5226be1e93ae13131ae3f22287190411389
- github.com/pydantic/pydantic-ai/commit/c3fd1cc1f15fdbf750d78e4e3ec1e8b4d6a3d920
- github.com/pydantic/pydantic-ai/commit/fb92ccfc3ca2735dab877e2ed73856681bf72ad1
- github.com/pydantic/pydantic-ai/pull/8397
- github.com/pydantic/pydantic-ai/pull/8399
- github.com/pydantic/pydantic-ai/pull/8418
- github.com/pydantic/pydantic-ai/pull/8433
- github.com/pydantic/pydantic-ai/pull/8434
- github.com/pydantic/pydantic-ai/releases/tag/v1.107.6
- github.com/pydantic/pydantic-ai/releases/tag/v2.44.0
- github.com/pydantic/pydantic-ai/security/advisories/GHSA-fpf4-vwcp-v4hp
- nvd.nist.gov/vuln/detail/CVE-2026-107290
Code Behaviors & Features
Detect and mitigate CVE-2026-107290 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →