Pydantic AI: Excessive resource use when local web fetching converts nested HTML
Summary
Applications using Pydantic AI's local web-fetch tool can experience excessive CPU and memory use when it converts attacker-controlled HTML. An agent must fetch the affected page; provider-native web fetching is not affected.
Details
Nested block elements cause HTML-to-Markdown conversion to reprocess accumulated text at each level and can greatly expand the intermediate output. The response-body limit bounds downloaded bytes, while the returned-content limit is applied only after conversion. On current releases, conversion runs in a worker thread but can still consume substantial resources and delay other work in the process. Older releases performed conversion on the event loop.
Mitigation
Upgrade to a patched release of pydantic-ai or pydantic-ai-slim. If you cannot upgrade yet, avoid using local web fetching for attacker-controlled HTML.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| pydantic-ai PyPI | >= 1.77.0, < 1.107.7 | 1.107.7 |
| >= 2.0.0b1, < 2.52.0 | 2.52.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400, CWE-407
- Also known as
- CVE-2026-107287
- github.com/pydantic/pydantic-ai/security/advisories/GHSA-v36g-jcw9-x7cw
- github.com/pydantic/pydantic-ai/pull/8984
- github.com/pydantic/pydantic-ai/pull/8985
- github.com/pydantic/pydantic-ai/commit/2b247add4950bef61d352e7ca8aefbd20539180c
- github.com/pydantic/pydantic-ai/commit/2fd38792693da00a3ca5412aeffb436787af3545
- github.com/pydantic/pydantic-ai
- github.com/pydantic/pydantic-ai/releases/tag/v1.107.7
- github.com/pydantic/pydantic-ai/releases/tag/v2.52.0