Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency can retain shared concurrency slots because anyio.CapacityLimiter associates an acquired slot with the borrowing task while streaming cleanup can run in a different task. Early stream termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can therefore leave capacity occupied, eventually preventing later requests that share the long-lived limiter from proceeding and causing a denial of service. Agent-level max_concurrency and non-streaming model requests are not affected. This issue is fixed in version 2.53.0.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in concurrency‑limited models within Pydantic AI that allow a streamed request to retain its concurrency slot even after early termination. When a request ends prematurely, an anyio.CapacityLimiter keeps the acquired slot tied to the original task, preventing subsequent requests from obtaining a slot. This flaw leads to a denial of service by exhausting available concurrency slots. The weakness is identified as CWE-772, representing a lack of proper resource release.

Affected Systems

Affected products are Pydantic AI (pydantic:pydantic-ai) and Pydantic AI Slim (pydantic:pydantic-ai-slim), all releases from version 2.10.0 up through 2.53.0. The issue is present only in streamed requests processed by ConcurrencyLimitedModel or limit_model_concurrency. Non‑streaming calls and agent‑level max_concurrency settings are unaffected.

Risk and Exploitability

The CVSS score of 7.5 categorizes the issue as high severity. Although a public EPSS score is not reported, the possibility of exploitation exists when an attacker can trigger early stream termination, cancellations, or consumer exceptions against a service using these models. The flaw is not present in the CISA KEV catalog. Mitigation is straightforward by upgrading to v2.53.0 or later; until then, the risk is moderate to high depending on service exposure.

Generated by OpenCVE AI on October 8, 2026 at 17:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to Pydantic AI version 2.53.0 or later.
  • Apply vendor patch or upgrade to the fixed release if available.
  • Disable concurrency limiting for stream requests or avoid using limit_model_concurrency until a patch is installed.

Generated by OpenCVE AI on October 8, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Description Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency can retain shared concurrency slots because anyio.CapacityLimiter associates an acquired slot with the borrowing task while streaming cleanup can run in a different task. Early stream termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can therefore leave capacity occupied, eventually preventing later requests that share the long-lived limiter from proceeding and causing a denial of service. Agent-level max_concurrency and non-streaming model requests are not affected. This issue is fixed in version 2.53.0.
Title Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early
Weaknesses CWE-772
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:27:24.185Z

Reserved: 2026-10-07T15:53:23.586Z

Link: CVE-2026-107286

cve-icon Vulnrichment

Updated: 2026-10-08T17:27:17.682Z

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:40.753

Modified: 2026-10-08T18:17:16.307

Link: CVE-2026-107286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:30:17Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime