{"data":{"id":"50b10c4f-0bdc-4920-b85f-6b493906bc1f","title":"GHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`","summary":"Pydantic AI's local web-fetch tool (`web_fetch_tool`, also the local fallback for the `WebFetch` capability) runs response decoding, title extraction and HTML-to-markdown conversion on the event loop, where several steps take time that grows quadratically with server-controlled input. An attacker who can steer the agent through untrusted prompts can make it fetch a page of one to two megabytes that blocks the event loop for minutes, stalling other agent runs and requests in the process. The fix is in the upgrade listed below.","solution":"Upgrade to a patched version. The title is now found with a single linear scan, the conversion steps run in linear time, and decoding, title extraction and conversion all run in a worker thread. A charset naming a codec that isn't a text encoding, and a page too deeply nested to convert, are reported back to the model as a failed fetch instead of aborting the run; a JSON body too deeply nested to parse is returned as plain text.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-fpf4-vwcp-v4hp","publishedAt":"2026-10-08T16:48:25.000Z","cveId":"CVE-2026-107290","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["pydantic-ai-slim@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai-slim@>= 1.77.0, < 1.107.6 (fixed: 1.107.6)","pydantic-ai@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai@>= 1.77.0, < 1.107.6 (fixed: 1.107.6)"],"affectedPackageNames":["pydantic-ai-slim","pydantic-ai"],"affectedVendors":[],"affectedVendorsRaw":["Pydantic AI"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.0042,"epssCheckedAt":"2026-10-10T03:00:41.257Z","kevDateAdded":null,"advisoryAliases":["GHSA-fpf4-vwcp-v4hp"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T16:48:25.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}