GHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`
- Identifiers
- CVE-2026-107290GHSA-fpf4-vwcp-v4hp
- Published
- Record updated
Summary
Pydantic AI's local web-fetch tool (`web_fetch_tool`, also the local fallback for the `WebFetch` capability) runs response decoding, title extraction and HTML-to-markdown conversion on the event loop, where several steps take time that grows quadratically with server-controlled input. An attacker who can steer the agent through untrusted prompts can make it fetch a page of one to two megabytes that blocks the event loop for minutes, stalling other agent runs and requests in the process. The fix is in the upgrade listed below.
Mitigation
Upgrade to a patched version. The title is now found with a single linear scan, the conversion steps run in linear time, and decoding, title extraction and conversion all run in a worker thread. A charset naming a codec that isn't a text encoding, and a page too deeply nested to convert, are reported back to the model as a failed fetch instead of aborting the run; a JSON body too deeply nested to parse is returned as plain text.
Related items
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- HighCVE-2026-107286: Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until…Similar attack · NVD/CVE Database
- MediumPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetSimilar attack · The Hacker News
- MediumCVE-2026-93679: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to…Similar attack · NVD/CVE Database