GHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl
- Identifiers
- CVE-2026-107294GHSA-v2xh-2vp8-57h8
- Published
- Record updated
- Affected
- pydantic-ai-slim >= 2.0.0b1, <= 2.23.0, fixed in 2.24.0
- pydantic-ai-slim >= 1.77.0, < 1.107.2, fixed in 1.107.2
- pydantic-ai >= 2.0.0b1, <= 2.23.0, fixed in 2.24.0
- and 1 more
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.4%
Summary
Pydantic AI's local web-fetch tool (`web_fetch_tool`, or the `WebFetch` capability's local fallback) and its `FileUrl` media downloads (`ImageUrl`, `DocumentUrl`, `VideoUrl`, `AudioUrl`) read the entire HTTP response body into memory before applying any size limit. An application that exposes the web-fetch tool to untrusted prompts can be driven to fetch a URL that streams a very large body, exhausting process memory and crashing the worker. The issue affects availability only; SSRF protections remain in place and there is no confidentiality or integrity impact.
Mitigation
Upgrade to `2.24.0` or later (v2) or `1.107.2` or later (v1). Patched versions enforce a default 50 MiB cap on web-fetch and `FileUrl` downloads while streaming; pass `None` to the limit to restore the previous unbounded behavior.
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumHermes Agent - Pre-Authentication Memory ExhaustionSimilar attack · Tenable Research Advisories
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database
- HighCVE-2026-107286: Pydantic AI streamed requests leak concurrency slots, causing denial of serviceSimilar attack · NVD/CVE Database