{"data":{"ecosystem":"pypi","name":"pydantic-ai","url":"https://aisecwatch.com/packages/pypi/pydantic-ai","latestVersion":"2.55.0","firstReleaseAt":"2024-05-20T00:08:05.260Z","repository":"https://github.com/pydantic/pydantic-ai","llm":{"exposure":"direct","depth":0,"integratedAt":"2024-05-20T00:08:05.260Z","integratedVersion":"0.0.0","sdks":["pydantic-ai"],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"pydantic-ai-examples","versionSpec":"==2.55.0","scope":"extra:examples"},{"ecosystem":"pypi","name":"pydantic-ai-slim","versionSpec":"==2.55.0","scope":"runtime"}],"advisories":[{"id":"0c8c812f-2b3d-4786-9df2-cb76f35bfdc2","url":"https://aisecwatch.com/issues/0c8c812f-2b3d-4786-9df2-cb76f35bfdc2","cveId":"CVE-2026-107287","title":"GHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTML","headline":null,"severity":"medium","publishedAt":"2026-10-08T17:40:50.000Z","affected":["pydantic-ai-slim@>= 2.0.0b1, < 2.52.0 (fixed: 2.52.0)","pydantic-ai-slim@>= 1.77.0, < 1.107.7 (fixed: 1.107.7)","pydantic-ai@>= 2.0.0b1, < 2.52.0 (fixed: 2.52.0)","pydantic-ai@>= 1.77.0, < 1.107.7 (fixed: 1.107.7)"],"epssScore":0.00277},{"id":"dc2acd77-32e5-472a-b1af-32fa3af8cff5","url":"https://aisecwatch.com/issues/dc2acd77-32e5-472a-b1af-32fa3af8cff5","cveId":"CVE-2026-107292","title":"GHSA-q2xc-rrxj-58x9: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not validate the `Host` header","headline":null,"severity":"medium","publishedAt":"2026-10-08T17:16:39.000Z","affected":["pydantic-ai-slim@>= 2.0.0b1, < 2.30.0 (fixed: 2.30.0)","pydantic-ai-slim@>= 1.34.0, < 1.107.5 (fixed: 1.107.5)","pydantic-ai@>= 2.0.0b1, < 2.30.0 (fixed: 2.30.0)","pydantic-ai@>= 1.34.0, < 1.107.5 (fixed: 1.107.5)"],"epssScore":0.00132},{"id":"4804dac9-4e8d-40f2-809b-51aa8f8fbb91","url":"https://aisecwatch.com/issues/4804dac9-4e8d-40f2-809b-51aa8f8fbb91","cveId":"CVE-2026-107295","title":"GHSA-h4xc-3qfq-jf93: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpoint","headline":null,"severity":"high","publishedAt":"2026-10-08T17:16:36.000Z","affected":["pydantic-ai-slim@>= 2.0.0b1, < 2.28.0 (fixed: 2.28.0)","pydantic-ai-slim@>= 1.34.0, < 1.107.4 (fixed: 1.107.4)","pydantic-ai@>= 2.0.0b1, < 2.28.0 (fixed: 2.28.0)","pydantic-ai@>= 1.34.0, < 1.107.4 (fixed: 1.107.4)"],"epssScore":0.0016},{"id":"b5fd5924-7a5d-4fb8-9f98-141acb67d91a","url":"https://aisecwatch.com/issues/b5fd5924-7a5d-4fb8-9f98-141acb67d91a","cveId":"CVE-2026-107293","title":"GHSA-3gh4-cghq-f8v4: Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `include_content=False`","headline":null,"severity":"low","publishedAt":"2026-10-08T17:16:32.000Z","affected":["pydantic-ai-slim@>= 2.0.0b1, < 2.27.1 (fixed: 2.27.1)","pydantic-ai-slim@>= 0.3.4, < 1.107.4 (fixed: 1.107.4)","pydantic-ai@>= 2.0.0b1, < 2.27.1 (fixed: 2.27.1)","pydantic-ai@>= 0.3.4, < 1.107.4 (fixed: 1.107.4)"],"epssScore":0.00336},{"id":"bc63fe00-429b-4947-9de0-fba6a75b039d","url":"https://aisecwatch.com/issues/bc63fe00-429b-4947-9de0-fba6a75b039d","cveId":"CVE-2026-107294","title":"GHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl","headline":null,"severity":"medium","publishedAt":"2026-10-08T17:16:28.000Z","affected":["pydantic-ai-slim@>= 2.0.0b1, <= 2.23.0 (fixed: 2.24.0)","pydantic-ai-slim@>= 1.77.0, < 1.107.2 (fixed: 1.107.2)","pydantic-ai@>= 2.0.0b1, <= 2.23.0 (fixed: 2.24.0)","pydantic-ai@>= 1.77.0, < 1.107.2 (fixed: 1.107.2)"],"epssScore":0.00434},{"id":"50b10c4f-0bdc-4920-b85f-6b493906bc1f","url":"https://aisecwatch.com/issues/50b10c4f-0bdc-4920-b85f-6b493906bc1f","cveId":"CVE-2026-107290","title":"GHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`","headline":null,"severity":"medium","publishedAt":"2026-10-08T16:48:25.000Z","affected":["pydantic-ai-slim@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai-slim@>= 1.77.0, < 1.107.6 (fixed: 1.107.6)","pydantic-ai@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai@>= 1.77.0, < 1.107.6 (fixed: 1.107.6)"],"epssScore":0.0042},{"id":"4c397576-c968-4822-9b6b-30cd8805733d","url":"https://aisecwatch.com/issues/4c397576-c968-4822-9b6b-30cd8805733d","cveId":"CVE-2026-107291","title":"GHSA-4x9p-g9wm-8q7f: Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False`","headline":null,"severity":"low","publishedAt":"2026-10-08T16:48:16.000Z","affected":["pydantic-ai-slim@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai-slim@>= 0.3.4, < 1.107.6 (fixed: 1.107.6)","pydantic-ai@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai@>= 0.3.4, < 1.107.6 (fixed: 1.107.6)"],"epssScore":0.00392},{"id":"58dc5497-fc53-403d-9a2b-3ec01674c56b","url":"https://aisecwatch.com/issues/58dc5497-fc53-403d-9a2b-3ec01674c56b","cveId":"CVE-2026-107289","title":"GHSA-vmxc-h2x2-jmf3: Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifiers","headline":null,"severity":"medium","publishedAt":"2026-10-08T16:48:06.000Z","affected":["pydantic-ai-slim@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai-slim@>= 1.56.0, < 1.107.6 (fixed: 1.107.6)","pydantic-ai@>= 2.0.0b1, < 2.44.0 (fixed: 2.44.0)","pydantic-ai@>= 1.56.0, < 1.107.6 (fixed: 1.107.6)"],"epssScore":0.00328},{"id":"37a3eab1-1512-4673-9015-f5794666947b","url":"https://aisecwatch.com/issues/37a3eab1-1512-4673-9015-f5794666947b","cveId":"CVE-2026-107286","title":"CVE-2026-107286: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until…","headline":"Pydantic AI streamed requests leak concurrency slots, causing denial of service","severity":"high","publishedAt":"2026-10-08T15:17:40.753Z","affected":["pydantic-ai@>= 2.10.0, < 2.53.0 (fixed: 2.53.0)","pydantic-ai-slim@>= 2.10.0, < 2.53.0 (fixed: 2.53.0)"],"epssScore":0.0045},{"id":"509b53c0-f39a-403b-80b6-6651b9824494","url":"https://aisecwatch.com/issues/509b53c0-f39a-403b-80b6-6651b9824494","cveId":"CVE-2026-54249","title":"CVE-2026-54249: Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0…","headline":"Pydantic AI UI adapters forward unvalidated UploadedFile references","severity":"medium","publishedAt":"2026-07-29T21:17:47.323Z","affected":["pydantic-ai-slim@>= 1.65.0, < 1.106.0 (fixed: 1.106.0)","pydantic-ai-slim@>= 2.0.0b1, < 2.0.0b6 (fixed: 2.0.0b6)","pydantic-ai@>= 1.65.0, < 1.106.0 (fixed: 1.106.0)","pydantic-ai@>= 2.0.0b1, < 2.0.0b6 (fixed: 2.0.0b6)"],"epssScore":0.00315},{"id":"dc3ad503-128f-4c24-bbbb-0543e3a2412c","url":"https://aisecwatch.com/issues/dc3ad503-128f-4c24-bbbb-0543e3a2412c","cveId":"CVE-2026-48782","title":"GHSA-cg7w-rg45-pc59: pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)","headline":null,"severity":"medium","publishedAt":"2026-06-26T19:17:56.000Z","affected":["pydantic-ai-slim@>= 1.56.0, < 1.102.0 (fixed: 1.102.0)","pydantic-ai@>= 1.56.0, < 1.102.0 (fixed: 1.102.0)","pydantic-ai@>= 2.0.0b1, < 2.0.0b3 (fixed: 2.0.0b3)","pydantic-ai-slim@>= 2.0.0b1, < 2.0.0b3 (fixed: 2.0.0b3)"],"epssScore":0.00417},{"id":"8dfa2b2b-10ef-47f7-a7bf-d2d09604e047","url":"https://aisecwatch.com/issues/8dfa2b2b-10ef-47f7-a7bf-d2d09604e047","cveId":"CVE-2026-46678","title":"GHSA-cqp8-fcvh-x7r3: Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)","headline":null,"severity":"medium","publishedAt":"2026-05-21T21:35:18.000Z","affected":["pydantic-ai-slim@>= 1.56.0, < 1.99.0 (fixed: 1.99.0)","pydantic-ai@>= 1.56.0, < 1.99.0 (fixed: 1.99.0)"],"epssScore":0.0038},{"id":"3500036a-ab44-4b8f-9a31-21c6c1f123ea","url":"https://aisecwatch.com/issues/3500036a-ab44-4b8f-9a31-21c6c1f123ea","cveId":"CVE-2026-25580","title":"CVE-2026-25580: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to…","headline":"Pydantic AI server-side request forgery in URL download via message history","severity":"high","publishedAt":"2026-02-06T21:16:17.167Z","affected":["pydantic-ai@>= 0.0.26, < 1.56.0 (fixed: 1.56.0)","pydantic-ai-slim@>= 0.0.26, < 1.56.0 (fixed: 1.56.0)"],"epssScore":0.00743},{"id":"b2eccf7c-18f6-40ea-8a87-ca54074ecc47","url":"https://aisecwatch.com/issues/b2eccf7c-18f6-40ea-8a87-ca54074ecc47","cveId":"CVE-2026-25640","title":"CVE-2026-25640: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to…","headline":"Pydantic AI web UI path traversal via version query parameter","severity":"high","publishedAt":"2026-02-06T20:16:11.110Z","affected":["pydantic-ai@>= 1.34.0, < 1.51.0 (fixed: 1.51.0)","pydantic-ai-slim@>= 1.34.0, < 1.51.0 (fixed: 1.51.0)"],"epssScore":0.00462}],"checkedAt":"2026-10-09T21:48:46.627Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}