CVE-2026-107294
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Oct 08, 2026
Vendor
unknown
Description
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HTTP response body before enforcing content-size controls. An attacker-influenced URL can stream an arbitrarily large response that exhausts process memory and crashes the worker; affected media types include ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. SSRF protections remain effective, and the impact is limited to availability. This issue is fixed in versions 1.107.2 and 2.24.0.
References
- https://github.com/pydantic/pydantic-ai/commit/7a64d049c3f5271a975cd1d64b2fa876d83ede1d
- https://github.com/pydantic/pydantic-ai/commit/e3824a58c82864ed26afb2887619834a4eb86cc8
- https://github.com/pydantic/pydantic-ai/pull/7141
- https://github.com/pydantic/pydantic-ai/pull/7308
- https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.2