Skip to content
MediumVulnerabilityLLM-specific

GHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl

Published
Record updated
View JSON
Affected
  • pydantic-ai-slim >= 2.0.0b1, <= 2.23.0, fixed in 2.24.0
  • pydantic-ai-slim >= 1.77.0, < 1.107.2, fixed in 1.107.2
  • pydantic-ai >= 2.0.0b1, <= 2.23.0, fixed in 2.24.0
  • and 1 more
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

Pydantic AI's local web-fetch tool (`web_fetch_tool`, or the `WebFetch` capability's local fallback) and its `FileUrl` media downloads (`ImageUrl`, `DocumentUrl`, `VideoUrl`, `AudioUrl`) read the entire HTTP response body into memory before applying any size limit. An application that exposes the web-fetch tool to untrusted prompts can be driven to fetch a URL that streams a very large body, exhausting process memory and crashing the worker. The issue affects availability only; SSRF protections remain in place and there is no confidentiality or integrity impact.

Mitigation

Upgrade to `2.24.0` or later (v2) or `1.107.2` or later (v1). Patched versions enforce a default 50 MiB cap on web-fetch and `FileUrl` downloads while streaming; pass `None` to the limit to restore the previous unbounded behavior.