PatchSiren cyber security CVE debrief
CVE-2026-107287 pydantic CVE debrief
Pydantic AI, a Python agent framework for building applications and workflows with Generative AI, is vulnerable to excessive resource use when local web fetching converts nested HTML. This issue affects versions from 1.77.0 until 1.107.7 and 2.52.0 of Pydantic AI and Pydantic AI Slim. The vulnerability can cause a model-directed fetch to delay other work in the process, potentially impacting system performance, especially in critical tasks or high-traffic scenarios. Defenders and developers should assess exposure and prioritize patching or mitigating this vulnerability.
- Vendor
- pydantic
- Product
- pydantic-ai
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders and developers using Pydantic AI, especially in critical tasks or high-traffic scenarios, should assess exposure and prioritize patching or mitigating this vulnerability.
Why it matters
This vulnerability in Pydantic AI can cause excessive resource use, potentially impacting system performance and responsiveness. Defenders and developers should assess exposure, prioritize patching, and implement compensating controls to mitigate the risk.
- Potential delay in processing due to excessive resource use
- Possible impact on system performance and responsiveness
- Need for verification of system resource usage and monitoring
- Priority for patching or mitigating the vulnerability in critical environments
Technical summary
The vulnerability in Pydantic AI allows for excessive resource use when local web fetching converts nested HTML. This can cause a model-directed fetch to delay other work in the process, potentially impacting system performance. The issue affects versions from 1.77.0 until 1.107.7 and 2.52.0 of Pydantic AI and Pydantic AI Slim. Defenders should prioritize patching or mitigating this vulnerability, especially in environments where Pydantic AI is used for critical tasks or in high-traffic scenarios, and consider implementing compensating controls.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability, especially in environments where Pydantic AI is used for critical tasks or in high-traffic scenarios.
Recommended defensive actions
- Assess exposure and prioritize patching for Pydantic AI versions 1.77.0 to 1.107.7 and 2.0.0b1 to 2.52.0
- Implement compensating controls, such as monitoring system resources and limiting the impact of delayed processes
- Verify system performance and resource usage to detect potential anomalies
- Consider using provider-native web fetching as an alternative to local web fetching
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including affected versions and potential impact. However, there is limited information on actual exploitation or victim impact. Defenders should verify system resource usage and monitor for potential anomalies. The vulnerability allows for excessive resource use when local web fetching converts nested HTML, which can cause a model-directed fetch to delay other work in the process.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107287 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107287
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107287 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107287
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Pydantic AI: Excessive resource use when local web fetching converts nested HTML
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107287.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-v36g-jcw9-x7cw
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/8984
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/8985
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/2b247add4950bef61d352e7ca8aefbd20539180c
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/2fd38792693da00a3ca5412aeffb436787af3545
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.7
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/releases/tag/v2.52.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.