CVE-2026-107286
Received Received - Intake

Denial of Service in Pydantic AI Framework

Vulnerability report for CVE-2026-107286, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency can retain shared concurrency slots because anyio.CapacityLimiter associates an acquired slot with the borrowing task while streaming cleanup can run in a different task. Early stream termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can therefore leave capacity occupied, eventually preventing later requests that share the long-lived limiter from proceeding and causing a denial of service. Agent-level max_concurrency and non-streaming model requests are not affected. This issue is fixed in version 2.53.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pydantic pydantic-ai >= 2.10.0, < 2.53.0
pydantic pydantic-ai-slim >= 2.10.0, < 2.53.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-772 The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107286 is a concurrency-related vulnerability in Pydantic AI versions 2.10.0 to 2.53.0. It occurs when streaming requests through ConcurrencyLimitedModel retain shared concurrency slots after completion or interruption. The issue arises because the slot is acquired by one task but released by another, such as during early stream termination or cancellation. This improper cleanup permanently reduces available concurrency, eventually blocking subsequent requests and causing a denial of service.

Detection Guidance

Check if your system uses Pydantic AI versions between 2.10.0 and 2.53.0 by running: pip show pydantic-ai. If installed, verify if streaming endpoints use ConcurrencyLimitedModel with shared limiters. Monitor for RuntimeError exceptions or blocked requests during streaming operations.

Impact Analysis

This vulnerability can cause denial of service by exhausting shared concurrency slots. Applications exposing affected streaming endpoints may experience blocked requests, RuntimeError exceptions, or failures in later requests. Non-streaming requests and agent-level max_concurrency settings are unaffected. The impact is highest in systems with shared long-lived model limiters where clients repeatedly start and disconnect streams.

Compliance Impact

This vulnerability primarily impacts system availability by causing denial of service through improper concurrency slot management. While it does not directly expose or leak data, prolonged service unavailability could potentially violate compliance requirements for data processing timeliness under GDPR or HIPAA. The denial of service risk may conflict with availability requirements in these regulations.

Mitigation Strategies

Upgrade to Pydantic AI version 2.53.0 or later using pip install --upgrade pydantic-ai. Alternatively, switch to agent-level max_concurrency settings or avoid streaming through concurrency-limited models to prevent slot leaks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107286. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart