PatchSiren cyber security CVE debrief
CVE-2026-107291 pydantic CVE debrief
Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False`. This issue affects Pydantic AI versions from 0.3.4 until 1.107.6 and 2.44.0. Despite OpenTelemetry instrumentation being configured with `InstrumentationSettings(include_content=False)`, sensitive agent content can still be exported through exception events, error status descriptions, and model_request_parameters. The exposed data includes tool feedback, provider error bodies, runtime instructions, and structured-output templates. This issue does not grant new access to agent data, and deployments that do not use `include_content=False` are not affected by the setting bypass. The issue is fixed in versions 1.107.6 and 2.44.0.
- Vendor
- pydantic
- Product
- pydantic-ai
- CVSS
- LOW 2.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders and security teams responsible for Pydantic AI deployments, especially those using OpenTelemetry instrumentation, should assess their exposure and prioritize remediation.
Why it matters
CVE-2026-107291 affects Pydantic AI deployments using OpenTelemetry instrumentation with `include_content=False`, potentially exposing sensitive agent content. Defenders should assess exposure, prioritize remediation, and update to fixed versions to prevent potential misuse of exposed information.
- Verification of Pydantic AI deployment configurations and versions to ensure they are not exposed to sensitive content leakage.
- Potential exposure of tool feedback, provider error bodies, runtime instructions, and structured-output templates to readers of the configured telemetry backend.
- Need for immediate remediation to prevent potential misuse of exposed information.
- Review and adjustment of telemetry backend configurations to handle sensitive data properly.
Technical summary
The Pydantic AI OpenTelemetry instrumentation can export sensitive agent content through exception events, error status descriptions, and model_request_parameters even when configured with `InstrumentationSettings(include_content=False)`. This affects versions from 0.3.4 until 1.107.6 and 2.44.0. The issue is fixed in versions 1.107.6 and 2.44.0. Defenders should assess exposure and prioritize remediation for Pydantic AI deployments using OpenTelemetry instrumentation with `include_content=False`, focusing on potential exposure of tool feedback, provider error bodies, runtime instructions, and structured-output templates.
Defensive priority
Defenders should assess exposure and prioritize remediation for Pydantic AI deployments using OpenTelemetry instrumentation with `include_content=False`.
Recommended defensive actions
- Assess Pydantic AI deployment versions and configurations for exposure to sensitive content leakage.
- Verify if OpenTelemetry instrumentation is configured with `include_content=False`.
- Update to Pydantic AI versions 1.107.6 or 2.44.0, or later, to fix the issue.
- Review and adjust telemetry backend configurations to ensure proper handling of sensitive data.
- Monitor for and respond to potential misuse of exposed information.
Evidence notes
The CVE record and source item provide details on the affected versions and the configuration that leads to sensitive content exposure. Official references from Pydantic AI and NIST NVD offer additional context.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107291 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107291
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107291 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107291
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107291.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-4x9p-g9wm-8q7f
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/8403
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/8404
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/8408
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/8428
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/8429
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/4e013c51a50659aba2adf7853bfb22bb77f6a518
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.