Excessive Resource Consumption in Pydantic AI Framework
CVE-2026-107287
6.5MEDIUM
What is CVE-2026-107287?
The Pydantic AI framework has a vulnerability that allows excessive CPU and memory usage during HTML-to-Markdown conversions when handling deeply nested elements in attacker-controlled HTML. This issue arises because the conversion processes accumulate text that may greatly expand before a content limit is reached, enabling a model-directed fetch to delay other tasks. This vulnerability affects versions 1.77.0 through 1.107.7 and 2.52.0, highlighting the need for users to update to the fixed versions 1.107.7 and 2.52.0 to mitigate potential performance issues.
Affected Version(s)
pydantic-ai >= 1.77.0, < 1.107.7 < 1.77.0, 1.107.7
pydantic-ai >= 2.0.0b1, < 2.52.0 < 2.0.0b1, 2.52.0
pydantic-ai-slim >= 1.77.0, < 1.107.7 < 1.77.0, 1.107.7
