CVE-2026-107287
Received
Received - Intake
Resource Exhaustion in Pydantic AI HTML-to-Markdown Conversion
Vulnerability report for CVE-2026-107287, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: GitHub, Inc.
Description
Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.7 and 2.52.0, the local web_fetch_tool and the WebFetch local fallback can consume excessive CPU and memory during HTML-to-Markdown conversion of attacker-controlled HTML containing deeply nested block elements. Conversion repeatedly reprocesses accumulated text and can greatly expand intermediate output before the returned-content limit is applied, allowing a model-directed fetch to delay other work in the process. Provider-native web fetching is not affected. This issue is fixed in versions 1.107.7 and 2.52.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pydantic | pydantic-ai | >= 1.77.0, < 1.107.7 |
| pydantic | pydantic-ai | >= 2.0.0b1, < 2.52.0 |
| pydantic | pydantic-ai-slim | >= 1.77.0, < 1.107.7 |
| pydantic | pydantic-ai-slim | >= 2.0.0b1, < 2.52.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |
| CWE-407 | An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached. |