Excessive Resource Consumption in Pydantic AI Framework
CVE-2026-107287

6.5MEDIUM

Key Information:

Vendor

Pydantic

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107287?

The Pydantic AI framework has a vulnerability that allows excessive CPU and memory usage during HTML-to-Markdown conversions when handling deeply nested elements in attacker-controlled HTML. This issue arises because the conversion processes accumulate text that may greatly expand before a content limit is reached, enabling a model-directed fetch to delay other tasks. This vulnerability affects versions 1.77.0 through 1.107.7 and 2.52.0, highlighting the need for users to update to the fixed versions 1.107.7 and 2.52.0 to mitigate potential performance issues.

Affected Version(s)

pydantic-ai >= 1.77.0, < 1.107.7 < 1.77.0, 1.107.7

pydantic-ai >= 2.0.0b1, < 2.52.0 < 2.0.0b1, 2.52.0

pydantic-ai-slim >= 1.77.0, < 1.107.7 < 1.77.0, 1.107.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.