Vulnerability  ·  2026-10-09

Pydantic AI web_fetch_tool / WebFetch local-fallback denial-of-service and telemetry data-leak cluster (8 low/medium issues)

VulnerabilityLow impactGlobalCVE-2026-107286
A coordinated batch of 8 Pydantic AI advisories published 2026-10-08 (CVSS 2.3–7.5): several resource-exhaustion flaws in the local web_fetch_tool/WebFetch fallback triggered by attacker-controlled HTML (quadratic title extraction, HTML-to-Markdown CPU/memory blowup, buffering before size limits), a blocked-domain normalization bypass, a concurrency-slot retention DoS in limit_model_concurrency, and two OpenTelemetry cases where include_content=False still exports sensitive agent content through exception messages and retry prompts.
These are agent-tool robustness gaps: an attacker who can feed content to an agent's web-fetch can stall the agent or exhaust the hosting process, and the OTel cases undermine the explicit 'don't log prompt content' guarantee baked into the framework's privacy settings — a silent data-leak into observability systems for AI deployments processing sensitive data.
Attacker-controlled HTML documents served to the agent's web-fetch tool trigger CPU/memory exhaustion in the HTML-to-Markdown pipeline or consume unbounded memory before size limits are enforced; or, in the telemetry cases, sensitive agent prompt/response content is exported to OpenTelemetry backends even when include_content=False is set, violating the caller's redaction intent.
pydantic-ai various ranges: ConcurrencyLimitedModel/limit_model_concurrency (CVE-2026-107286, ≤2.53.0); FileUrl force_download='allow-local'/allow_local_urls (CVE-2026-107289); HTML-to-Markdown CPU/mem DoS (CVE-2026-107287); quadratic title/whitespace processing DoS (CVE-2026-107290); response buffering before content-size enforcement (CVE-2026-107294); blocked_domains normalization bypass (CVE-2026-107288); OTel include_content=False still leaking content via exception.message (CVE-2026-107291) and retry prompts (CVE-2026-107293)
Upgrade to pydantic-ai 1.107.x/2.x per the individual fixes (commits listed on NVD); disable allow-local URL fetching unless needed; cap fetch sizes upstream; for telemetry, verify trace redaction after upgrade or avoid OTel export of agent spans where content secrecy is required.
NVD — CVE-2026-107286NVD — CVE-2026-107287NVD — CVE-2026-107291 (OTel leak)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →