Disclosure summary
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback process server-controlled responses with quadratic title extraction, whitespace normalization, and ordered-list numbering. An attacker-controlled page of modest size can therefore block the event loop for an extended period, stalling other agent runs and requests, while unsupported codecs or excessive HTML or JSON nesting can abort an individual run. This issue is fixed in versions 1.107.6 and 2.44.0.
Source-reported weakness categories
CWE-1333
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107290
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-fpf4-vwcp-v4hp
Open original source · Updated Oct 08, 2026
Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | pydantic-ai | >= 1.77.0, < 1.107.6 | 1.107.6 |
| pip | pydantic-ai | >= 2.0.0b1, < 2.44.0 | 2.44.0 |
| pip | pydantic-ai-slim | >= 1.77.0, < 1.107.6 | 1.107.6 |
| pip | pydantic-ai-slim | >= 2.0.0b1, < 2.44.0 | 2.44.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
PUBLISHED 2026-10-08T13:17:14-04:00
MODIFIED 2026-10-09T12:17:21-04:00
INGESTED 2026-10-10T20:55:03-04:00