Impact
The vulnerability lies in concurrency‑limited models within Pydantic AI that allow a streamed request to retain its concurrency slot even after early termination. When a request ends prematurely, an anyio.CapacityLimiter keeps the acquired slot tied to the original task, preventing subsequent requests from obtaining a slot. This flaw leads to a denial of service by exhausting available concurrency slots. The weakness is identified as CWE-772, representing a lack of proper resource release.
Affected Systems
Affected products are Pydantic AI (pydantic:pydantic-ai) and Pydantic AI Slim (pydantic:pydantic-ai-slim), all releases from version 2.10.0 up through 2.53.0. The issue is present only in streamed requests processed by ConcurrencyLimitedModel or limit_model_concurrency. Non‑streaming calls and agent‑level max_concurrency settings are unaffected.
Risk and Exploitability
The CVSS score of 7.5 categorizes the issue as high severity. Although a public EPSS score is not reported, the possibility of exploitation exists when an attacker can trigger early stream termination, cancellations, or consumer exceptions against a service using these models. The flaw is not present in the CISA KEV catalog. Mitigation is straightforward by upgrading to v2.53.0 or later; until then, the risk is moderate to high depending on service exposure.
OpenCVE Enrichment