CVE-2026-107290

Published: Ott 08, 2026 Last Modified: Ott 08, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,5
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback process server-controlled responses with quadratic title extraction, whitespace normalization, and ordered-list numbering. An attacker-controlled page of modest size can therefore block the event loop for an extended period, stalling other agent runs and requests, while unsupported codecs or excessive HTML or JSON nesting can abort an individual run. This issue is fixed in versions 1.107.6 and 2.44.0.

1333

Inefficient Regular Expression Complexity

Draft
Common Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu)
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/pydantic/pydantic-ai/commit/2faa6181d8a17d83bc9516d035c5270d…
https://github.com/pydantic/pydantic-ai/commit/9cdc952e4c3319e85a3e04f2de49fbbb…
https://github.com/pydantic/pydantic-ai/commit/a93ea5226be1e93ae13131ae3f222871…
https://github.com/pydantic/pydantic-ai/commit/c3fd1cc1f15fdbf750d78e4e3ec1e8b4…
https://github.com/pydantic/pydantic-ai/commit/fb92ccfc3ca2735dab877e2ed7385668…
https://github.com/pydantic/pydantic-ai/pull/8397
https://github.com/pydantic/pydantic-ai/pull/8399
https://github.com/pydantic/pydantic-ai/pull/8418
https://github.com/pydantic/pydantic-ai/pull/84332
https://github.com/pydantic/pydantic-ai/pull/8434
https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6
https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0
https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-fpf4-vwcp-v4hp