Denial of Service Vulnerability in Pydantic AI Framework
CVE-2026-107286

7.5HIGH

Key Information:

Vendor

Pydantic

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107286?

The Pydantic AI framework, used for building applications with Generative AI, has a vulnerability that affects versions 2.10.0 through 2.52.0. This issue involves the ConcurrencyLimitedModel and limit_model_concurrency, where streamed requests retain shared concurrency slots incorrectly due to the association with the borrowing task. This can lead to situations where early stream terminations or consumer exceptions prevent subsequent requests from being processed, ultimately causing a denial of service. Resolution for this issue is available in version 2.53.0.

Affected Version(s)

pydantic-ai >= 2.10.0, < 2.53.0

pydantic-ai-slim >= 2.10.0, < 2.53.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.