CVE-2026-107290
MEDIUM
6,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback process server-controlled responses with quadratic title extraction, whitespace normalization, and ordered-list numbering. An attacker-controlled page of modest size can therefore block the event loop for an extended period, stalling other agent runs and requests, while unsupported codecs or excessive HTML or JSON nesting can abort an individual run. This issue is fixed in versions 1.107.6 and 2.44.0.
1333
Inefficient Regular Expression Complexity
DraftCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu)
Applicable Platforms
All platforms may be affected
https://github.com/pydantic/pydantic-ai/commit/2faa6181d8a17d83bc9516d035c5270d…
https://github.com/pydantic/pydantic-ai/commit/9cdc952e4c3319e85a3e04f2de49fbbb…
https://github.com/pydantic/pydantic-ai/commit/a93ea5226be1e93ae13131ae3f222871…
https://github.com/pydantic/pydantic-ai/commit/c3fd1cc1f15fdbf750d78e4e3ec1e8b4…
https://github.com/pydantic/pydantic-ai/commit/fb92ccfc3ca2735dab877e2ed7385668…
https://github.com/pydantic/pydantic-ai/pull/8397
https://github.com/pydantic/pydantic-ai/pull/8399
https://github.com/pydantic/pydantic-ai/pull/8418
https://github.com/pydantic/pydantic-ai/pull/84332
https://github.com/pydantic/pydantic-ai/pull/8434
https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6
https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0
https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-fpf4-vwcp-v4hp