Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback process server-controlled responses with quadratic title extraction, whitespace normalization, and ordered-list numbering. An attacker-controlled page of modest size can therefore block the event loop for an extended period, stalling other agent runs and requests, while unsupported codecs or excessive HTML or JSON nesting can abort an individual run. This issue is fixed in versions 1.107.6 and 2.44.0.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via event loop blockage
Action: Apply Patch
AI Analysis

Impact

An attacker that can control the contents of a web page fetched by Pydantic AI’s local web_fetch_tool can cause the event loop to block for an extended period due to a quadratic algorithm that extracts titles, normalizes whitespace and processes ordered lists. The blocking stalls concurrent agent runs and outgoing requests, and highly nested or unsupported HTML or JSON can cause a run to abort. The flaw is a typical implementation error that leads to resource exhaustion and denial of service.

Affected Systems

The affected packages are pydantic:pydantic-ai and pydantic:pydantic-ai-slim. Any installed version from 1.77.0 up to but not including 1.107.6, and any 2.x release up to but not including 2.44.0, is vulnerable. Versions 1.107.6 and 2.44.0 and later contain the fix.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a local agent exposing the web_fetch tool to a malicious page; an attacker merely needs to trigger the agent to load a crafted resource to exhaust its event loop. While the issue is not a remote code execution flaw, it compromises availability and could be leveraged as a component of a broader denial‑of‑service campaign.

Generated by OpenCVE AI on October 8, 2026 at 17:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the pydantic‑ai package to version 1.107.6 or later, or to 2.44.0 or later.
  • If an upgrade is not immediately possible, restrict the use of web_fetch to trusted URLs or enforce a strict timeout for fetch operations.
  • Modify the agent configuration to run web_fetch in an isolated worker or apply application‑level resource limits to prevent single operations from monopolizing the event loop.

Generated by OpenCVE AI on October 8, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fpf4-vwcp-v4hp Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`
History

Thu, 08 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Pydantic
Pydantic pydantic-ai
Vendors & Products Pydantic
Pydantic pydantic-ai

Thu, 08 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback process server-controlled responses with quadratic title extraction, whitespace normalization, and ordered-list numbering. An attacker-controlled page of modest size can therefore block the event loop for an extended period, stalling other agent runs and requests, while unsupported codecs or excessive HTML or JSON nesting can abort an individual run. This issue is fixed in versions 1.107.6 and 2.44.0.
Title Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Pydantic Pydantic-ai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T16:09:04.272Z

Reserved: 2026-10-07T15:53:23.586Z

Link: CVE-2026-107290

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T17:17:14.413

Modified: 2026-10-08T20:35:31.200

Link: CVE-2026-107290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:30:17Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity