CVE-2026-107294
Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HTTP response body before enforcing content-size controls. An attacker-influenced URL can stream an arbitrarily large response that exhausts process memory and crashes the worker; affected media types include ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. SSRF protections remain effective, and the impact is limited to availability. This issue is fixed in versions 1.107.2 and 2.24.0.
| CWE | CWE-400 |
| Vendor | pydantic |
| Product | pydantic-ai |
| Published | Oct 8, 2026 |
Get instant alerts for pydantic pydantic-ai
Be the first to know when new medium vulnerabilities affecting pydantic pydantic-ai are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H