PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107291 pydantic CVE debrief

Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False`. This issue affects Pydantic AI versions from 0.3.4 until 1.107.6 and 2.44.0. Despite OpenTelemetry instrumentation being configured with `InstrumentationSettings(include_content=False)`, sensitive agent content can still be exported through exception events, error status descriptions, and model_request_parameters. The exposed data includes tool feedback, provider error bodies, runtime instructions, and structured-output templates. This issue does not grant new access to agent data, and deployments that do not use `include_content=False` are not affected by the setting bypass. The issue is fixed in versions 1.107.6 and 2.44.0.

Vendor
pydantic
Product
pydantic-ai
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders and security teams responsible for Pydantic AI deployments, especially those using OpenTelemetry instrumentation, should assess their exposure and prioritize remediation.

Why it matters

CVE-2026-107291 affects Pydantic AI deployments using OpenTelemetry instrumentation with `include_content=False`, potentially exposing sensitive agent content. Defenders should assess exposure, prioritize remediation, and update to fixed versions to prevent potential misuse of exposed information.

  • Verification of Pydantic AI deployment configurations and versions to ensure they are not exposed to sensitive content leakage.
  • Potential exposure of tool feedback, provider error bodies, runtime instructions, and structured-output templates to readers of the configured telemetry backend.
  • Need for immediate remediation to prevent potential misuse of exposed information.
  • Review and adjustment of telemetry backend configurations to handle sensitive data properly.

Technical summary

The Pydantic AI OpenTelemetry instrumentation can export sensitive agent content through exception events, error status descriptions, and model_request_parameters even when configured with `InstrumentationSettings(include_content=False)`. This affects versions from 0.3.4 until 1.107.6 and 2.44.0. The issue is fixed in versions 1.107.6 and 2.44.0. Defenders should assess exposure and prioritize remediation for Pydantic AI deployments using OpenTelemetry instrumentation with `include_content=False`, focusing on potential exposure of tool feedback, provider error bodies, runtime instructions, and structured-output templates.

Defensive priority

Defenders should assess exposure and prioritize remediation for Pydantic AI deployments using OpenTelemetry instrumentation with `include_content=False`.

Recommended defensive actions

  • Assess Pydantic AI deployment versions and configurations for exposure to sensitive content leakage.
  • Verify if OpenTelemetry instrumentation is configured with `include_content=False`.
  • Update to Pydantic AI versions 1.107.6 or 2.44.0, or later, to fix the issue.
  • Review and adjust telemetry backend configurations to ensure proper handling of sensitive data.
  • Monitor for and respond to potential misuse of exposed information.

Evidence notes

The CVE record and source item provide details on the affected versions and the configuration that leads to sensitive content exposure. Official references from Pydantic AI and NIST NVD offer additional context.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107291 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107291

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107291 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107291

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107291.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-4x9p-g9wm-8q7f

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/pull/8403

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/pull/8404

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/pull/8408

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/pull/8428

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/pull/8429

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/commit/4e013c51a50659aba2adf7853bfb22bb77f6a518

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.