AI and data stack advisories

Severe, 6 weeks2048Projects319

2048 severe, 6 weeks · 319 projects

pydantic-aiGHSA-v2xh-2vp8-57h8

Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl

pydantic-ai

CVE-2026-107294 · Published Oct 8, 2026

Medium6.5
Fix: upgrade to 1.107.2 or later (2 fixed versions below)
GitHub advisory

Summary

Several remote-content download paths in Pydantic AI buffered the entire HTTP response body into memory before enforcing any size limit. An application that exposes the local web-fetch tool (web_fetch_tool, or the WebFetch capability's local fallback) to untrusted prompts can be driven to fetch an attacker-chosen URL that streams a very large body, exhausting process memory and crashing the worker. The same unbounded buffering applied to FileUrl media downloads (ImageUrl, DocumentUrl, VideoUrl, AudioUrl).

This is an availability issue only. SSRF protections (scheme allowlist, private-IP and cloud-metadata blocking) are unaffected; there is no confidentiality or integrity impact.

Details

The download helpers read the full response body before applying content-size controls, so an existing text-length limit only truncated *after* the whole body was already in memory, and media downloads had no wire-level cap at all. A single large response could grow process memory without bound .

Who Is Affected

You are affected if your application registers the local web-fetch tool (or relies on the WebFetch capability's local fallback) and exposes the agent to untrusted prompts, or if it downloads large remote FileUrls influenced by untrusted input. Applications that only fetch developer-controlled URLs are not exposed to the model-chosen attack...

Affected versions

PackageAffectedFixed in
pydantic-ai
PyPI
>= 1.77.0, < 1.107.21.107.2
>= 2.0.0b1, < 2.24.02.24.0
Details and references

### Summary Several remote-content download paths in Pydantic AI buffered the entire HTTP response body into memory before enforcing any size limit. An application that exposes the local web-fetch tool (`web_fetch_tool`, or the `WebFetch` capability's local fallback) to untrusted prompts can be driven to fetch an attacker-chosen URL that streams a very large body, exhausting process memory and crashing the worker. The same unbounded buffering applied to `FileUrl` media downloads (`ImageUrl`, `DocumentUrl`, `VideoUrl`, `AudioUrl`). This is an **availability** issue only. SSRF protections (scheme allowlist, private-IP and cloud-metadata blocking) are unaffected; there is no confidentiality or integrity impact. ### Details The download helpers read the full response body before applying content-size controls, so an existing text-length limit only truncated *after* the whole body was already in memory, and media downloads had no wire-level cap at all. A single large response could grow process memory without bound . ### Who Is Affected You are affected if your application registers the local web-fetch tool (or relies on the `WebFetch` capability's local fallback) and exposes the agent to untrusted prompts, or if it downloads large remote `FileUrl`s influenced by untrusted input. Applications that only fetch developer-controlled URLs are not exposed to the model-chosen attack path. ### Remediation Upgrade to `2.24.0` or later (v2) or `1.107.2` or later (v1). Patched versions enforce a default 50 MiB cap on web-fetch and `FileUrl` downloads while streaming; pass `None` to the limit to restore the previous unbounded behavior. ### Credits Identified during internal review of media-download hardening.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-400, CWE-770
Also known as
CVE-2026-107294

More pydantic-ai advisories

All pydantic-ai