PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107294 pydantic CVE debrief

Pydantic AI is vulnerable to unbounded memory use when downloading remote content via web_fetch or FileUrl. This issue, affecting versions 1.77.0 through 1.107.2 and 2.24.0, can lead to a denial-of-service (DoS) attack, causing the worker to crash due to memory exhaustion. The vulnerability is limited to availability impact, and SSRF protections remain effective.

Vendor
pydantic
Product
pydantic-ai
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for systems using Pydantic AI, especially those handling remote content downloads, should assess exposure and prioritize patching or mitigating this vulnerability to prevent potential DoS attacks.

Why it matters

Defenders should prioritize patching or mitigating CVE-2026-107294 to prevent potential DoS attacks. Assess exposure for systems using Pydantic AI, especially those handling remote content downloads. The vulnerability's impact is limited to availability, and SSRF protections remain effective. Evidence is limited, and verification is required to confirm exploitation or victim impact.

  • Denial-of-service (DoS) attacks may be possible
  • Memory exhaustion can cause worker crashes
  • Availability impact requires verification

Technical summary

Pydantic AI is vulnerable to unbounded memory use when downloading remote content via web_fetch or FileUrl. This issue affects versions 1.77.0 through 1.107.2 and 2.24.0. An attacker-influenced URL can stream an arbitrarily large response, exhausting process memory and crashing the worker. The impact is limited to availability, and SSRF protections remain effective. Affected product deployments should be assessed for exposure, and defenders should prioritize patching or mitigating this vulnerability to prevent potential DoS attacks.

Defensive priority

Defenders should prioritize patching or mitigating this vulnerability to prevent potential DoS attacks. Assess exposure for systems using Pydantic AI, especially those handling remote content downloads.

Recommended defensive actions

  • Patch Pydantic AI to version 1.107.2 or 2.24.0
  • Assess exposure for systems using Pydantic AI
  • Implement monitoring for potential DoS attacks
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is limited information on potential exploitation or victim impact. Defenders should verify the vulnerability's impact and confirm affected systems. Evidence is limited, and verification tasks are required to confirm exploitation or victim impact. Limited source information is available, and defenders should exercise caution when assessing exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107294 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107294

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107294 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107294

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107294.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-v2xh-2vp8-57h8

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/pull/7141

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/pull/7308

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/commit/7a64d049c3f5271a975cd1d64b2fa876d83ede1d

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/commit/e3824a58c82864ed26afb2887619834a4eb86cc8

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.2

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/pydantic/pydantic-ai/releases/tag/v2.24.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.