CVE-2026-107293
Received Received - Intake

OpenTelemetry Instrumentation Information Disclosure in Pydantic AI

Vulnerability report for CVE-2026-107293, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.4 and 2.27.1, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can export retry prompts outside tool calls in gen_ai.input.messages and pydantic_ai.all_messages. Agents using NativeOutput, PromptedOutput, or output validators on text output can therefore disclose validation feedback, including invalid model values quoted by that feedback, to readers of the telemetry backend. Tool-call retries and deployments that do not use include_content=False are not affected by this specific path. This issue is fixed in versions 1.107.4 and 2.27.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
pydantic pydantic-ai >= 0.3.4, < 1.107.4
pydantic pydantic-ai >= 2.0.0b1, < 2.27.1
pydantic pydantic-ai-slim >= 0.3.4, < 1.107.4
pydantic pydantic-ai-slim >= 2.0.0b1, < 2.27.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.
CWE-212 The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Pydantic AI, a Python agent framework for Generative AI. When OpenTelemetry instrumentation is configured with include_content=False, it can accidentally export retry prompts outside tool calls in gen_ai.input.messages and pydantic_ai.all_messages. This may expose validation feedback, including invalid model values, to telemetry backend readers.

Detection Guidance

To detect this vulnerability, check if your Pydantic AI application uses OpenTelemetry instrumentation with include_content=False and logs retry prompts. Inspect OpenTelemetry traces for gen_ai.input.messages or pydantic_ai.all_messages containing validation feedback or invalid model outputs. Verify if versions are below 1.107.4 or 2.27.1.

Impact Analysis

If you use Pydantic AI versions between 0.3.4 and 1.107.4 or 2.27.1 with OpenTelemetry instrumentation set to include_content=False, sensitive validation feedback or invalid model values could be disclosed to unauthorized users accessing the telemetry backend.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by exposing sensitive validation feedback or invalid model outputs through OpenTelemetry telemetry data. If telemetry is sent to third-party observability vendors or less trusted systems, this may constitute unauthorized data disclosure under these regulations.

Mitigation Strategies

Upgrade Pydantic AI to version 1.107.4 or 2.27.1 or later to address the vulnerability. If using OpenTelemetry instrumentation, ensure InstrumentationSettings(include_content=False) is not configured to prevent prompt exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107293. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart