PatchSiren cyber security CVE debrief
CVE-2026-107286 pydantic CVE debrief
CVE-2026-107286 debrief: Pydantic AI's ConcurrencyLimitedModel can retain slots when streamed requests end early, potentially causing denial of service. This issue arises from anyio.CapacityLimiter associating an acquired slot with the borrowing task, while streaming cleanup can run in a different task. Early stream termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can therefore leave capacity occupied, eventually preventing later requests that share the long-lived limiter from proceeding.
- Vendor
- pydantic
- Product
- pydantic-ai
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders and developers using Pydantic AI's ConcurrencyLimitedModel should assess exposure and prioritize updates to prevent potential denial of service. They should review configurations, monitor for early stream termination, and adjust debounce_by settings as needed to mitigate the vulnerability. Security teams and operators managing Pydantic AI deployments should also be aware of the potential impact and take necessary actions to secure their systems.
Why it matters
CVE-2026-107286: Pydantic AI's ConcurrencyLimitedModel can retain slots when streamed requests end early, potentially causing denial of service. Defenders should prioritize verifying and updating Pydantic AI installations.
- Denial of service through slot retention in ConcurrencyLimitedModel.
- Potential service disruption due to early stream termination.
- Need for verification and updates to prevent exploitation.
Technical summary
Pydantic AI's ConcurrencyLimitedModel can retain shared concurrency slots when streamed requests end early, potentially causing denial of service. This issue is caused by anyio.CapacityLimiter associating an acquired slot with the borrowing task while streaming cleanup can run in a different task. The problem is fixed in version 2.53.0 and can be mitigated by adjusting ConcurrencyLimitedModel configurations and monitoring for early stream termination. Agent-level max_concurrency and non-streaming model requests are not affected.
Defensive priority
Defenders should prioritize verifying and updating Pydantic AI installations to prevent potential denial of service.
Recommended defensive actions
- Verify Pydantic AI version and update to 2.53.0 or later if using a vulnerable version.
- Review and adjust ConcurrencyLimitedModel configurations to prevent slot retention.
- Monitor for early stream termination and adjust debounce_by settings as needed.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and source item provide details on the vulnerability in Pydantic AI's ConcurrencyLimitedModel. The issue allows streamed requests to retain shared concurrency slots when they end early, potentially causing denial of service.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107286 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107286
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107286 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107286
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107286.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-6fqq-452j-qhrp
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/9478
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/453f19feeb7ab1d789f9393b1723c6a73b3d77b2
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/releases/tag/v2.53.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.