Data Exposure in Pydantic AI Framework by OpenTelemetry Instrumentation
CVE-2026-107291

2.3LOW

Key Information:

Vendor

Pydantic

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107291?

The Pydantic AI framework, designed for leveraging Generative AI applications, has a vulnerability related to OpenTelemetry instrumentation. When the configuration option 'InstrumentationSettings(include_content=False)' is used, sensitive information such as error messages, runtime instructions, and detailed model request parameters can still be exported through various events. This can potentially expose critical operational insights and execution details to unauthorized users accessing the telemetry backend. Although this setting, when properly configured, does not grant new access to agent data, systems using the aforementioned option are at risk. To mitigate this issue, users should update to versions 1.107.6 or 2.44.0 where the vulnerability has been addressed.

Affected Version(s)

pydantic-ai >= 0.3.4, < 1.107.6 < 0.3.4, 1.107.6

pydantic-ai >= 2.0.0b1, < 2.44.0 < 2.0.0b1, 2.44.0

pydantic-ai-slim >= 0.3.4, < 1.107.6 < 0.3.4, 1.107.6

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.