CVE-2026-107294: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl
Several remote-content download paths in Pydantic AI buffered the entire HTTP response body into memory before enforcing any size limit. An application that exposes the local web-fetch tool (web_fetch_tool, or the WebFetch capability’s local fallback) to untrusted prompts can be driven to fetch an attacker-chosen URL that streams a very large body, exhausting process memory and crashing the worker. The same unbounded buffering applied to FileUrl media downloads (ImageUrl, DocumentUrl, VideoUrl, AudioUrl).
This is an availability issue only. SSRF protections (scheme allowlist, private-IP and cloud-metadata blocking) are unaffected; there is no confidentiality or integrity impact.
References
- github.com/advisories/GHSA-v2xh-2vp8-57h8
- github.com/pydantic/pydantic-ai/commit/7a64d049c3f5271a975cd1d64b2fa876d83ede1d
- github.com/pydantic/pydantic-ai/commit/e3824a58c82864ed26afb2887619834a4eb86cc8
- github.com/pydantic/pydantic-ai/pull/7141
- github.com/pydantic/pydantic-ai/pull/7308
- github.com/pydantic/pydantic-ai/releases/tag/v1.107.2
- github.com/pydantic/pydantic-ai/releases/tag/v2.24.0
- github.com/pydantic/pydantic-ai/security/advisories/GHSA-v2xh-2vp8-57h8
- nvd.nist.gov/vuln/detail/CVE-2026-107294
Code Behaviors & Features
Detect and mitigate CVE-2026-107294 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →