Impact
An attacker that can control the contents of a web page fetched by Pydantic AI’s local web_fetch_tool can cause the event loop to block for an extended period due to a quadratic algorithm that extracts titles, normalizes whitespace and processes ordered lists. The blocking stalls concurrent agent runs and outgoing requests, and highly nested or unsupported HTML or JSON can cause a run to abort. The flaw is a typical implementation error that leads to resource exhaustion and denial of service.
Affected Systems
The affected packages are pydantic:pydantic-ai and pydantic:pydantic-ai-slim. Any installed version from 1.77.0 up to but not including 1.107.6, and any 2.x release up to but not including 2.44.0, is vulnerable. Versions 1.107.6 and 2.44.0 and later contain the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a local agent exposing the web_fetch tool to a malicious page; an attacker merely needs to trigger the agent to load a crafted resource to exhaust its event loop. While the issue is not a remote code execution flaw, it compromises availability and could be leveraged as a component of a broader denial‑of‑service campaign.
OpenCVE Enrichment
Github GHSA