GHSA-v36g-jcw9-x7cw

Suggest an improvement
Source
https://github.com/advisories/GHSA-v36g-jcw9-x7cw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-v36g-jcw9-x7cw/GHSA-v36g-jcw9-x7cw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v36g-jcw9-x7cw
Aliases
  • CVE-2026-107287
Published
2026-10-08T17:40:50Z
Modified
2026-10-08T18:00:09Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Pydantic AI: Excessive resource use when local web fetching converts nested HTML
Details

Summary

Applications using Pydantic AI's local web-fetch tool can experience excessive CPU and memory use when it converts attacker-controlled HTML. An agent must fetch the affected page; provider-native web fetching is not affected.

Details

Nested block elements cause HTML-to-Markdown conversion to reprocess accumulated text at each level and can greatly expand the intermediate output. The response-body limit bounds downloaded bytes, while the returned-content limit is applied only after conversion. On current releases, conversion runs in a worker thread but can still consume substantial resources and delay other work in the process. Older releases performed conversion on the event loop.

Mitigation

Upgrade to a patched release of pydantic-ai or pydantic-ai-slim. If you cannot upgrade yet, avoid using local web fetching for attacker-controlled HTML.

Database specific
{
    "cwe_ids": [
        "CWE-400",
        "CWE-407"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T17:40:50Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

PyPI / pydantic-ai

Package

Name
pydantic-ai
View open source insights on deps.dev
Purl
pkg:pypi/pydantic-ai

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.77.0
Fixed
1.107.7

Affected versions

1.*
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.84.1
1.85.0
1.85.1
1.86.0
1.86.1
1.87.0
1.88.0
1.89.0
1.89.1
1.90.0
1.91.0
1.92.0
1.93.0
1.94.0
1.95.0
1.95.1
1.96.0
1.96.1
1.97.0
1.98.0
1.99.0
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.107.1
1.107.2
1.107.4
1.107.5
1.107.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-v36g-jcw9-x7cw/GHSA-v36g-jcw9-x7cw.json"

PyPI / pydantic-ai

Package

Name
pydantic-ai
View open source insights on deps.dev
Purl
pkg:pypi/pydantic-ai

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0b1
Fixed
2.52.0

Affected versions

2.*
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.25.0
2.26.0
2.27.0
2.27.1
2.28.0
2.29.0
2.30.0
2.31.0
2.31.1
2.32.0
2.32.1
2.32.2
2.33.0
2.34.0
2.35.0
2.35.1
2.35.3
2.36.0
2.37.0
2.38.0
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.44.0
2.45.0
2.46.0
2.47.0
2.48.0
2.49.0
2.50.0
2.51.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-v36g-jcw9-x7cw/GHSA-v36g-jcw9-x7cw.json"

PyPI / pydantic-ai-slim

Package

Name
pydantic-ai-slim
View open source insights on deps.dev
Purl
pkg:pypi/pydantic-ai-slim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.77.0
Fixed
1.107.7

Affected versions

1.*
1.77.0
1.78.0
1.79.0
1.80.0
1.81.0
1.82.0
1.83.0
1.84.0
1.84.1
1.85.0
1.85.1
1.86.0
1.86.1
1.87.0
1.88.0
1.89.0
1.89.1
1.90.0
1.91.0
1.92.0
1.93.0
1.94.0
1.95.0
1.95.1
1.96.0
1.96.1
1.97.0
1.98.0
1.99.0
1.100.0
1.101.0
1.102.0
1.103.0
1.104.0
1.105.0
1.106.0
1.107.0
1.107.1
1.107.2
1.107.4
1.107.5
1.107.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-v36g-jcw9-x7cw/GHSA-v36g-jcw9-x7cw.json"

PyPI / pydantic-ai-slim

Package

Name
pydantic-ai-slim
View open source insights on deps.dev
Purl
pkg:pypi/pydantic-ai-slim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0b1
Fixed
2.52.0

Affected versions

2.*
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.5.1
2.6.0
2.7.0
2.8.0
2.9.0
2.9.1
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.16.0
2.17.0
2.18.0
2.19.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.25.0
2.26.0
2.27.0
2.27.1
2.28.0
2.29.0
2.30.0
2.31.0
2.31.1
2.32.0
2.32.1
2.32.2
2.33.0
2.34.0
2.35.0
2.35.1
2.35.3
2.36.0
2.37.0
2.38.0
2.39.0
2.40.0
2.41.0
2.42.0
2.43.0
2.44.0
2.45.0
2.46.0
2.47.0
2.48.0
2.49.0
2.50.0
2.51.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-v36g-jcw9-x7cw/GHSA-v36g-jcw9-x7cw.json"