---
id: CVE-2026-107290
title: >-
  Pydantic AI is a Python agent framework for building applications and
  workflows with Generative AI
summary: >-
  Pydantic AI is a Python agent framework for building applications and
  workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local
  web_fetch_tool and the WebFetch local fallback process server-controlled
  responses with q…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-1333
  - CWE-407
vendor: pydantic-ai
product: pydantic-ai
affected:
  - 'pydantic-ai >= 1.77.0, < 1.107.6'
  - 'pydantic-ai >= 2.0.0b1, < 2.44.0'
  - 'pydantic-ai-slim >= 1.77.0, < 1.107.6'
  - 'pydantic-ai-slim >= 2.0.0b1, < 2.44.0'
patched:
  - pydantic-ai 1.107.6
  - pydantic-ai 2.44.0
  - pydantic-ai-slim 1.107.6
  - pydantic-ai-slim 2.44.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:35:31.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107290'
references:
  - url: >-
      https://github.com/pydantic/pydantic-ai/commit/2faa6181d8a17d83bc9516d035c5270db8730fa0
    label: security-advisories@github.com
  - url: >-
      https://github.com/pydantic/pydantic-ai/commit/9cdc952e4c3319e85a3e04f2de49fbbb765bd38b
    label: security-advisories@github.com
  - url: >-
      https://github.com/pydantic/pydantic-ai/commit/a93ea5226be1e93ae13131ae3f22287190411389
    label: security-advisories@github.com
  - url: >-
      https://github.com/pydantic/pydantic-ai/commit/c3fd1cc1f15fdbf750d78e4e3ec1e8b4d6a3d920
    label: security-advisories@github.com
  - url: >-
      https://github.com/pydantic/pydantic-ai/commit/fb92ccfc3ca2735dab877e2ed73856681bf72ad1
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/pull/8397'
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/pull/8399'
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/pull/8418'
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/pull/84332'
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/pull/8434'
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6'
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-fpf4-vwcp-v4hp
    label: security-advisories@github.com
  - url: 'https://github.com/pydantic/pydantic-ai/pull/8433'
  - url: 'https://github.com/advisories/GHSA-fpf4-vwcp-v4hp'
tags:
  - nvd
  - ghsa
  - pip
  - cve.org
aliases:
  - GHSA-fpf4-vwcp-v4hp
ecosystem: pip
ingestedAt: '2026-10-08T16:52:14.778Z'
---

## Overview

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback process server-controlled responses with quadratic title extraction, whitespace normalization, and ordered-list numbering. An attacker-controlled page of modest size can therefore block the event loop for an extended period, stalling other agent runs and requests, while unsupported codecs or excessive HTML or JSON nesting can abort an individual run. This issue is fixed in versions 1.107.6 and 2.44.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107290)

Affected packages:

- `pydantic-ai >= 1.77.0, < 1.107.6`
- `pydantic-ai >= 2.0.0b1, < 2.44.0`
- `pydantic-ai-slim >= 1.77.0, < 1.107.6`
- `pydantic-ai-slim >= 2.0.0b1, < 2.44.0`

Patched in:

- `pydantic-ai 1.107.6`
- `pydantic-ai 2.44.0`
- `pydantic-ai-slim 1.107.6`
- `pydantic-ai-slim 2.44.0`

Source: https://github.com/advisories/GHSA-fpf4-vwcp-v4hp
