AI and data stack advisories

Severe, 6 weeks2048Projects319

2048 severe, 6 weeks · 319 projects

pydantic-aiGHSA-v36g-jcw9-x7cw

Pydantic AI: Excessive resource use when local web fetching converts nested HTML

pydantic-ai

CVE-2026-107287 · Published Oct 8, 2026

Medium6.5
Fix: upgrade to 1.107.7 or later (2 fixed versions below)
GitHub advisory

Summary

Applications using Pydantic AI's local web-fetch tool can experience excessive CPU and memory use when it converts attacker-controlled HTML. An agent must fetch the affected page; provider-native web fetching is not affected.

Details

Nested block elements cause HTML-to-Markdown conversion to reprocess accumulated text at each level and can greatly expand the intermediate output. The response-body limit bounds downloaded bytes, while the returned-content limit is applied only after conversion. On current releases, conversion runs in a worker thread but can still consume substantial resources and delay other work in the process. Older releases performed conversion on the event loop.

Mitigation

Upgrade to a patched release of pydantic-ai or pydantic-ai-slim. If you cannot upgrade yet, avoid using local web fetching for attacker-controlled HTML.

Affected versions

PackageAffectedFixed in
pydantic-ai
PyPI
>= 1.77.0, < 1.107.71.107.7
>= 2.0.0b1, < 2.52.02.52.0
Details and references

More pydantic-ai advisories

All pydantic-ai