CVE-2026-107291
Received Received - Intake

OpenTelemetry Instrumentation Exposes Sensitive Data in Pydantic AI

Vulnerability report for CVE-2026-107291, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.6 and 2.44.0, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can still export sensitive agent content through exception.message and exception.stacktrace events, error status descriptions, and model_request_parameters containing instructions or the prompted_output_template. The exposed data is available to readers of the configured telemetry backend and can include tool feedback, provider error bodies, runtime instructions, and structured-output templates even though message attributes are redacted. This issue does not grant new access to agent data, and deployments that do not use include_content=False are not affected by the setting bypass. This issue is fixed in versions 1.107.6 and 2.44.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
pydantic pydantic-ai >= 0.3.4, < 1.107.6
pydantic pydantic-ai >= 2.0.0b1, < 2.44.0
pydantic pydantic-ai-slim >= 0.3.4, < 1.107.6
pydantic pydantic-ai-slim >= 2.0.0b1, < 2.44.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.
CWE-212 The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Pydantic AI is a Python framework for building AI applications. A vulnerability exists in versions 0.3.4 to 1.107.6 and 2.44.0 where OpenTelemetry instrumentation with include_content=False still exports sensitive agent content through exception messages, stack traces, and model request parameters. This exposes tool feedback, provider errors, instructions, and templates to telemetry backend readers even though message attributes are redacted.

Detection Guidance

Check if your Pydantic AI deployment uses OpenTelemetry with InstrumentationSettings(include_content=False). Inspect telemetry backend logs for exposed agent content in exception messages, stack traces, error status descriptions, or model_request_parameters containing instructions or templates.

Impact Analysis

If you use affected Pydantic AI versions with OpenTelemetry and include_content=False, sensitive data like instructions, tool feedback, or error details could be exposed to anyone with access to your telemetry system. This does not grant new access but bypasses the intended redaction for certain telemetry events.

Compliance Impact

This vulnerability could lead to unauthorized exposure of sensitive data, potentially violating GDPR (data protection) or HIPAA (health information privacy) if the exposed content includes personal or protected health information. Organizations using affected versions may face compliance risks due to unintended data disclosure.

Mitigation Strategies

Upgrade Pydantic AI to versions 1.107.6 or 2.44.0 or later. If using OpenTelemetry, avoid InstrumentationSettings(include_content=False) configuration. Review telemetry backend access controls to limit exposure of sensitive data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107291. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart