Vulnerability GHSA-v36g-jcw9-x7cw

Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 hours ago
October 08, 2026 at 05:40 PM UTC
Pydantic AI: Excessive resource use when local web fetching converts nested HTML
1.77.0 - 1.107.6 and 2.0.0b1 - 2.51.0
1.77.0 - 1.107.6 and 2.0.0b1 - 2.51.0

Summary

Pydantic AI: Excessive resource use when local web fetching converts nested HTML

Details

Summary

Applications using Pydantic AI's local web-fetch tool can experience excessive CPU and memory use when it converts attacker-controlled HTML. An agent must fetch the affected page; provider-native web fetching is not affected.

Details

Nested block elements cause HTML-to-Markdown conversion to reprocess accumulated text at each level and can greatly expand the intermediate output. The response-body limit bounds downloaded bytes, while the returned-content limit is applied only after conversion. On current releases, conversion runs in a worker thread but can still consume substantial resources and delay other work in the process. Older releases performed conversion on the event loop.

Mitigation

Upgrade to a patched release of pydantic-ai or pydantic-ai-slim. If you cannot upgrade yet, avoid using local web fetching for attacker-controlled HTML.

Timeline

Published
5 hours ago
October 08, 2026 at 05:40 PM UTC
Fixed (1.107.7)
8 days ago
September 30, 2026 at 01:14 AM UTC
Fixed (1.107.7)
8 days ago
September 30, 2026 at 01:14 AM UTC
Fixed (2.52.0)
8 days ago
September 30, 2026 at 01:17 AM UTC
Fixed (2.52.0)
8 days ago
September 30, 2026 at 01:18 AM UTC
Last Modified
5 hours ago
October 08, 2026 at 06:00 PM UTC