CVE-2026-107294
MEDIUM
6,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HTTP response body before enforcing content-size controls. An attacker-influenced URL can stream an arbitrarily large response that exhausts process memory and crashes the worker; affected media types include ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. SSRF protections remain effective, and the impact is limited to availability. This issue is fixed in versions 1.107.2 and 2.24.0.
400
Uncontrolled Resource Consumption
DraftCommon Consequences
Security Scopes Affected:
Availability
Access Control
Other
Potential Impacts:
Dos: Crash, Exit, Or Restart
Dos: Resource Consumption (Cpu)
Dos: Resource Consumption (Memory)
Dos: Resource Consumption (Other)
Bypass Protection Mechanism
Other
Applicable Platforms
Technologies:
Not Technology-Specific, AI/ML
https://github.com/pydantic/pydantic-ai/commit/7a64d049c3f5271a975cd1d64b2fa876…
https://github.com/pydantic/pydantic-ai/commit/e3824a58c82864ed26afb2887619834a…
https://github.com/pydantic/pydantic-ai/pull/7141
https://github.com/pydantic/pydantic-ai/pull/7308
https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.2
https://github.com/pydantic/pydantic-ai/releases/tag/v2.24.0
https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-v2xh-2vp8-57h8