HighVulnerability
CVE-2026-107286: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-107286
- Published
- Record updated
Summary
Pydantic AI versions 2.10.0 through 2.53.0 have a flaw in streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency. Because anyio.CapacityLimiter ties an acquired slot to the borrowing task while streaming cleanup can run in a different task, early termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can leave shared concurrency slots occupied. Later requests on the long-lived limiter can then be blocked, causing a denial of service. Agent-level max_concurrency and non-streaming model requests are not affected.
Mitigation
Fixed in version 2.53.0.
Topics
Related items
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database
- MediumPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetSimilar attack · The Hacker News
- MediumCVE-2026-93679: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to…Similar attack · NVD/CVE Database