CVE-2026-107287

MEDIUM CVSS 3.1: 6.5 EPSS 0.28%
Updated Oct 09, 2026
Python
Parameter Value
CVSS 6.5 (MEDIUM)
Type CWE-400 (Uncontrolled Resource Consumption), CWE-407
Vendor Python
Public PoC No

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.7 and 2.52.0, the local web_fetch_tool and the WebFetch local fallback can consume excessive CPU and memory during HTML-to-Markdown conversion of attacker-controlled HTML containing deeply nested block elements. Conversion repeatedly reprocesses accumulated text and can greatly expand intermediate output before the returned-content limit is applied, allowing a model-directed fetch to delay other work in the process.

Provider-native web fetching is not affected. This issue is fixed in versions 1.107.7 and 2.52.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products

pydantic:pydantic-ai-slim pydantic:pydantic-ai