CVE-2026-107287
Received Received - Intake

Resource Exhaustion in Pydantic AI HTML-to-Markdown Conversion

Vulnerability report for CVE-2026-107287, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.7 and 2.52.0, the local web_fetch_tool and the WebFetch local fallback can consume excessive CPU and memory during HTML-to-Markdown conversion of attacker-controlled HTML containing deeply nested block elements. Conversion repeatedly reprocesses accumulated text and can greatly expand intermediate output before the returned-content limit is applied, allowing a model-directed fetch to delay other work in the process. Provider-native web fetching is not affected. This issue is fixed in versions 1.107.7 and 2.52.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
pydantic pydantic-ai >= 1.77.0, < 1.107.7
pydantic pydantic-ai >= 2.0.0b1, < 2.52.0
pydantic pydantic-ai-slim >= 1.77.0, < 1.107.7
pydantic pydantic-ai-slim >= 2.0.0b1, < 2.52.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Pydantic AI is a Python framework for building AI applications. This vulnerability affects versions between 1.77.0 and 1.107.7, and 2.52.0. It involves the local web_fetch_tool and its fallback, which can consume excessive CPU and memory when converting attacker-controlled HTML to Markdown. The issue occurs due to deeply nested block elements causing repeated reprocessing of text, expanding intermediate output before content limits are applied.

Detection Guidance

Detecting this vulnerability requires checking the installed version of Pydantic AI. Run pip show pydantic-ai or pip list | grep pydantic-ai to verify if your version is between 1.77.0 and 1.107.7 or 2.52.0. If so, the system is vulnerable.

Impact Analysis

This vulnerability can cause denial-of-service by consuming excessive system resources during HTML-to-Markdown conversion. It may delay or disrupt other processes in the same environment, especially if the system is handling multiple requests or tasks simultaneously.

Compliance Impact

This vulnerability primarily impacts system availability due to excessive CPU and memory consumption during HTML processing. While not directly violating GDPR or HIPAA, it could indirectly affect compliance by causing service disruptions that impact data processing operations or system reliability required under these regulations.

Mitigation Strategies

Upgrade Pydantic AI to version 1.107.7 or 2.52.0 or later immediately. Use pip install --upgrade pydantic-ai to apply the fix. Avoid using the local web_fetch_tool with untrusted HTML content until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107287. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart