Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HTTP response body before enforcing content-size controls. An attacker-influenced URL can stream an arbitrarily large response that exhausts process memory and crashes the worker; affected media types include ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. SSRF protections remain effective, and the impact is limited to availability. This issue is fixed in versions 1.107.2 and 2.24.0.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability occurs when the framework buffers an entire HTTP response body before enforcing size limits, allowing an attacker-controlled URL to cause unbounded memory usage and crash a worker. The flaw leads to a loss of availability; it does not directly compromise confidentiality or integrity. The weakness is a classic resource exhaustion issue as defined by CWE-400.

Affected Systems

The affected products are Pydantic’s pydantic‑ai and pydantic‑ai‑slim. Versions from 1.77.0 up through 1.107.2 and the 2.24.0 release are vulnerable. The issue is fixed starting with version 1.107.2 and 2.24.0.

Risk and Exploitability

The CVSS score of 6.5 classifies the flaw as Medium severity, and no EPSS data is available. It is not listed in the CISA KEV catalog. The likely attack vector is an application that uses the web_fetch_tool or FileUrl, where an attacker can supply a URL that streams an arbitrarily large response. Because the framework only performs size checks after buffering the entire response, the attacker can exhaust available process memory, causing a crash and denying service. SSRF protections remain functional, so the vulnerability does not provide additional network attack surface.

Generated by OpenCVE AI on October 8, 2026 at 18:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest patch to pydantic‑ai (v1.107.2 or v2.24.0) to fix the memory exhaustion bug.
  • If upgrading is not immediately possible, restrict the URLs used by web_fetch_tool and FileUrl to trusted domains and impose a lower maximum download size manually in the application.
  • Implement process isolation or resource limits (for example, cgroups or Docker memory limits) for workers that use the framework to mitigate potential crashes.

Generated by OpenCVE AI on October 8, 2026 at 18:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-v2xh-2vp8-57h8 Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl
History

Thu, 08 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Pydantic
Pydantic pydantic-ai
Vendors & Products Pydantic
Pydantic pydantic-ai

Thu, 08 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HTTP response body before enforcing content-size controls. An attacker-influenced URL can stream an arbitrarily large response that exhausts process memory and crashes the worker; affected media types include ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. SSRF protections remain effective, and the impact is limited to availability. This issue is fixed in versions 1.107.2 and 2.24.0.
Title Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Pydantic Pydantic-ai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T16:59:25.246Z

Reserved: 2026-10-07T15:53:23.586Z

Link: CVE-2026-107294

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T17:17:15.080

Modified: 2026-10-08T20:35:31.200

Link: CVE-2026-107294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption