Ad

CVE-2026-107294

MEDIUM CVSS 3.1: 6,5 EPSS 0.43%
Обновлено 9 октября 2026
Python
Параметр Значение
CVSS 6,5 (MEDIUM)
Тип уязвимости CWE-400 (Неконтролируемое потребление ресурсов)
Поставщик Python
Публичный эксплойт Нет

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HTTP response body before enforcing content-size controls. An attacker-influenced URL can stream an arbitrarily large response that exhausts process memory and crashes the worker; affected media types include ImageUrl, DocumentUrl, VideoUrl, and AudioUrl. SSRF protections remain effective, and the impact is limited to availability.

This issue is fixed in versions 1.107.2 and 2.24.0.

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Низкая
Легко эксплуатировать
Нужны права
Низкие
Нужны базовые права
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Нет
Нет утечки данных
Целостность
Нет
Нет модификации данных
Доступность
Высокое
Полный отказ в обслуживании

Строка CVSS v3.1