PatchSiren cyber security CVE debrief
CVE-2026-107294 pydantic CVE debrief
Pydantic AI is vulnerable to unbounded memory use when downloading remote content via web_fetch or FileUrl. This issue, affecting versions 1.77.0 through 1.107.2 and 2.24.0, can lead to a denial-of-service (DoS) attack, causing the worker to crash due to memory exhaustion. The vulnerability is limited to availability impact, and SSRF protections remain effective.
- Vendor
- pydantic
- Product
- pydantic-ai
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for systems using Pydantic AI, especially those handling remote content downloads, should assess exposure and prioritize patching or mitigating this vulnerability to prevent potential DoS attacks.
Why it matters
Defenders should prioritize patching or mitigating CVE-2026-107294 to prevent potential DoS attacks. Assess exposure for systems using Pydantic AI, especially those handling remote content downloads. The vulnerability's impact is limited to availability, and SSRF protections remain effective. Evidence is limited, and verification is required to confirm exploitation or victim impact.
- Denial-of-service (DoS) attacks may be possible
- Memory exhaustion can cause worker crashes
- Availability impact requires verification
Technical summary
Pydantic AI is vulnerable to unbounded memory use when downloading remote content via web_fetch or FileUrl. This issue affects versions 1.77.0 through 1.107.2 and 2.24.0. An attacker-influenced URL can stream an arbitrarily large response, exhausting process memory and crashing the worker. The impact is limited to availability, and SSRF protections remain effective. Affected product deployments should be assessed for exposure, and defenders should prioritize patching or mitigating this vulnerability to prevent potential DoS attacks.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability to prevent potential DoS attacks. Assess exposure for systems using Pydantic AI, especially those handling remote content downloads.
Recommended defensive actions
- Patch Pydantic AI to version 1.107.2 or 2.24.0
- Assess exposure for systems using Pydantic AI
- Implement monitoring for potential DoS attacks
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is limited information on potential exploitation or victim impact. Defenders should verify the vulnerability's impact and confirm affected systems. Evidence is limited, and verification tasks are required to confirm exploitation or victim impact. Limited source information is available, and defenders should exercise caution when assessing exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107294 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107294
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107294 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107294
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107294.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-v2xh-2vp8-57h8
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/7141
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/pull/7308
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/7a64d049c3f5271a975cd1d64b2fa876d83ede1d
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/commit/e3824a58c82864ed26afb2887619834a4eb86cc8
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.2
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/pydantic/pydantic-ai/releases/tag/v2.24.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.