Buffer Management Flaw in Pydantic AI WebFetch Capability
CVE-2026-107294
6.5MEDIUM
What is CVE-2026-107294?
A buffer management flaw exists in Pydantic AI's WebFetch tool, where the complete HTTP response body is buffered before content-size controls are enforced. This vulnerability, present in versions 1.77.0 to 1.107.2 and 2.24.0, allows an attacker to supply a crafted URL that streams an excessively large response. Consequently, this can lead to memory exhaustion and crash the worker process, affecting the application's availability. The flaw impacts media types such as ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. It has been resolved in updated versions 1.107.2 and 2.24.0.
Affected Version(s)
pydantic-ai >= 1.77.0, < 1.107.2 < 1.77.0, 1.107.2
pydantic-ai >= 2.0.0b1, < 2.24.0 < 2.0.0b1, 2.24.0
pydantic-ai-slim >= 1.77.0, < 1.107.2 < 1.77.0, 1.107.2
