CVE-2026-107290

medium

Description

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback process server-controlled responses with quadratic title extraction, whitespace normalization, and ordered-list numbering. An attacker-controlled page of modest size can therefore block the event loop for an extended period, stalling other agent runs and requests, while unsupported codecs or excessive HTML or JSON nesting can abort an individual run. This issue is fixed in versions 1.107.6 and 2.44.0.

References

https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-fpf4-vwcp-v4hp

https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0

https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6

https://github.com/pydantic/pydantic-ai/pull/8434

https://github.com/pydantic/pydantic-ai/pull/84332

https://github.com/pydantic/pydantic-ai/pull/8418

https://github.com/pydantic/pydantic-ai/pull/8399

https://github.com/pydantic/pydantic-ai/pull/8397

https://github.com/pydantic/pydantic-ai/commit/fb92ccfc3ca2735dab877e2ed73856681bf72ad1

https://github.com/pydantic/pydantic-ai/commit/c3fd1cc1f15fdbf750d78e4e3ec1e8b4d6a3d920

https://github.com/pydantic/pydantic-ai/commit/a93ea5226be1e93ae13131ae3f22287190411389

https://github.com/pydantic/pydantic-ai/commit/9cdc952e4c3319e85a3e04f2de49fbbb765bd38b

https://github.com/pydantic/pydantic-ai/commit/2faa6181d8a17d83bc9516d035c5270db8730fa0

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-95093

Details

Source: Mitre, NVD

Published: 2026-10-08

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium