{"data":{"id":"bc63fe00-429b-4947-9de0-fba6a75b039d","title":"GHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl","summary":"Pydantic AI's local web-fetch tool (`web_fetch_tool`, or the `WebFetch` capability's local fallback) and its `FileUrl` media downloads (`ImageUrl`, `DocumentUrl`, `VideoUrl`, `AudioUrl`) read the entire HTTP response body into memory before applying any size limit. An application that exposes the web-fetch tool to untrusted prompts can be driven to fetch a URL that streams a very large body, exhausting process memory and crashing the worker. The issue affects availability only; SSRF protections remain in place and there is no confidentiality or integrity impact.","solution":"Upgrade to `2.24.0` or later (v2) or `1.107.2` or later (v1). Patched versions enforce a default 50 MiB cap on web-fetch and `FileUrl` downloads while streaming; pass `None` to the limit to restore the previous unbounded behavior.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-v2xh-2vp8-57h8","publishedAt":"2026-10-08T17:16:28.000Z","cveId":"CVE-2026-107294","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["pydantic-ai-slim@>= 2.0.0b1, <= 2.23.0 (fixed: 2.24.0)","pydantic-ai-slim@>= 1.77.0, < 1.107.2 (fixed: 1.107.2)","pydantic-ai@>= 2.0.0b1, <= 2.23.0 (fixed: 2.24.0)","pydantic-ai@>= 1.77.0, < 1.107.2 (fixed: 1.107.2)"],"affectedPackageNames":["pydantic-ai-slim","pydantic-ai"],"affectedVendors":[],"affectedVendorsRaw":["Pydantic AI","web_fetch_tool","WebFetch capability","ImageUrl","DocumentUrl","VideoUrl","AudioUrl","FileUrl"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00434,"epssCheckedAt":"2026-10-10T02:56:51.777Z","kevDateAdded":null,"advisoryAliases":["GHSA-v2xh-2vp8-57h8"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T17:16:28.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":"plugin","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":null,"atlasIds":null}}