Skip to content
HighVulnerability

CVE-2026-107286: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until…

Identifier
CVE-2026-107286
Published
Record updated
View JSON

Summary

Pydantic AI versions 2.10.0 through 2.53.0 have a flaw in streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency. Because anyio.CapacityLimiter ties an acquired slot to the borrowing task while streaming cleanup can run in a different task, early termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can leave shared concurrency slots occupied. Later requests on the long-lived limiter can then be blocked, causing a denial of service. Agent-level max_concurrency and non-streaming model requests are not affected.

Mitigation

Fixed in version 2.53.0.