Buffer Management Flaw in Pydantic AI WebFetch Capability
CVE-2026-107294

6.5MEDIUM

Key Information:

Vendor

Pydantic

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107294?

A buffer management flaw exists in Pydantic AI's WebFetch tool, where the complete HTTP response body is buffered before content-size controls are enforced. This vulnerability, present in versions 1.77.0 to 1.107.2 and 2.24.0, allows an attacker to supply a crafted URL that streams an excessively large response. Consequently, this can lead to memory exhaustion and crash the worker process, affecting the application's availability. The flaw impacts media types such as ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. It has been resolved in updated versions 1.107.2 and 2.24.0.

Affected Version(s)

pydantic-ai >= 1.77.0, < 1.107.2 < 1.77.0, 1.107.2

pydantic-ai >= 2.0.0b1, < 2.24.0 < 2.0.0b1, 2.24.0

pydantic-ai-slim >= 1.77.0, < 1.107.2 < 1.77.0, 1.107.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.