Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. pydantic-ai
  4. ›
  5. CVE-2026-107294

CVE-2026-107294: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl

October 8, 2026

Several remote-content download paths in Pydantic AI buffered the entire HTTP response body into memory before enforcing any size limit. An application that exposes the local web-fetch tool (web_fetch_tool, or the WebFetch capability’s local fallback) to untrusted prompts can be driven to fetch an attacker-chosen URL that streams a very large body, exhausting process memory and crashing the worker. The same unbounded buffering applied to FileUrl media downloads (ImageUrl, DocumentUrl, VideoUrl, AudioUrl).

This is an availability issue only. SSRF protections (scheme allowlist, private-IP and cloud-metadata blocking) are unaffected; there is no confidentiality or integrity impact.

References

  • github.com/advisories/GHSA-v2xh-2vp8-57h8
  • github.com/pydantic/pydantic-ai/commit/7a64d049c3f5271a975cd1d64b2fa876d83ede1d
  • github.com/pydantic/pydantic-ai/commit/e3824a58c82864ed26afb2887619834a4eb86cc8
  • github.com/pydantic/pydantic-ai/pull/7141
  • github.com/pydantic/pydantic-ai/pull/7308
  • github.com/pydantic/pydantic-ai/releases/tag/v1.107.2
  • github.com/pydantic/pydantic-ai/releases/tag/v2.24.0
  • github.com/pydantic/pydantic-ai/security/advisories/GHSA-v2xh-2vp8-57h8
  • nvd.nist.gov/vuln/detail/CVE-2026-107294

Code Behaviors & Features

Detect and mitigate CVE-2026-107294 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.77.0 before 1.107.2, all versions starting from 2.0.0-b.1 before 2.24.0

Fixed versions

  • 1.107.2
  • 2.24.0

Solution

Upgrade to versions 1.107.2, 2.24.0 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption
  • CWE-770: Allocation of Resources Without Limits or Throttling

Source file

pypi/pydantic-ai/CVE-2026-107294.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 09 Oct 2026 12:22:58 +0000.