CVE-2026-107294
Received Received - Intake

Memory Exhaustion in Pydantic AI via HTTP Response Buffering

Vulnerability report for CVE-2026-107294, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HTTP response body before enforcing content-size controls. An attacker-influenced URL can stream an arbitrarily large response that exhausts process memory and crashes the worker; affected media types include ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. SSRF protections remain effective, and the impact is limited to availability. This issue is fixed in versions 1.107.2 and 2.24.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
pydantic pydantic-ai >= 1.77.0, < 1.107.2
pydantic pydantic-ai >= 2.0.0b1, < 2.24.0
pydantic pydantic-ai-slim >= 1.77.0, < 1.107.2
pydantic pydantic-ai-slim >= 2.0.0b1, < 2.24.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Pydantic AI versions between 1.77.0 and 1.107.2 and 2.24.0 have a flaw where web_fetch_tool, WebFetch local fallback, and remote FileUrl media downloads buffer the entire HTTP response before applying size limits. This allows an attacker to send a large response that consumes all available memory, crashing the application.

Detection Guidance

Detecting this vulnerability requires checking the installed version of Pydantic AI. Run: pip show pydantic-ai. If the version is between 1.77.0 and 1.107.1 or 2.24.0, the system is vulnerable. Monitor for crashes or memory exhaustion during HTTP requests or media downloads.

Impact Analysis

This vulnerability can cause denial-of-service by crashing the application due to memory exhaustion. It does not lead to data breaches or unauthorized access, as SSRF protections remain intact and only availability is affected.

Compliance Impact

This vulnerability primarily impacts system availability by causing memory exhaustion and process crashes, which could lead to service disruptions. It does not directly affect data confidentiality or integrity, so it is unlikely to violate GDPR or HIPAA requirements for data protection. However, repeated availability issues could indirectly impact compliance by failing to maintain system reliability required for processing personal or health data.

Mitigation Strategies

Upgrade Pydantic AI to version 1.107.2 or 2.24.0 immediately using pip install --upgrade pydantic-ai. If upgrading is not possible, restrict network access to untrusted URLs and monitor for unusual memory usage.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107294. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart