Impact
The vulnerability occurs when the framework buffers an entire HTTP response body before enforcing size limits, allowing an attacker-controlled URL to cause unbounded memory usage and crash a worker. The flaw leads to a loss of availability; it does not directly compromise confidentiality or integrity. The weakness is a classic resource exhaustion issue as defined by CWE-400.
Affected Systems
The affected products are Pydantic’s pydantic‑ai and pydantic‑ai‑slim. Versions from 1.77.0 up through 1.107.2 and the 2.24.0 release are vulnerable. The issue is fixed starting with version 1.107.2 and 2.24.0.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as Medium severity, and no EPSS data is available. It is not listed in the CISA KEV catalog. The likely attack vector is an application that uses the web_fetch_tool or FileUrl, where an attacker can supply a URL that streams an arbitrarily large response. Because the framework only performs size checks after buffering the entire response, the attacker can exhaust available process memory, causing a crash and denying service. SSRF protections remain functional, so the vulnerability does not provide additional network attack surface.
OpenCVE Enrichment
Github GHSA