CVE-2026-107294
Received
Received - Intake
Memory Exhaustion in Pydantic AI via HTTP Response Buffering
Vulnerability report for CVE-2026-107294, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: GitHub, Inc.
Description
Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HTTP response body before enforcing content-size controls. An attacker-influenced URL can stream an arbitrarily large response that exhausts process memory and crashes the worker; affected media types include ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. SSRF protections remain effective, and the impact is limited to availability. This issue is fixed in versions 1.107.2 and 2.24.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pydantic | pydantic-ai | >= 1.77.0, < 1.107.2 |
| pydantic | pydantic-ai | >= 2.0.0b1, < 2.24.0 |
| pydantic | pydantic-ai-slim | >= 1.77.0, < 1.107.2 |
| pydantic | pydantic-ai-slim | >= 2.0.0b1, < 2.24.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |