Pydantic AI: Excessive resource use when local web fetching converts nested HTML
Pydantic AI: Excessive resource use when local web fetching converts nested HTML
Medium severity. Affects pydantic-ai >= 1.77.0, < 1.107.7; pydantic-ai >= 2.0.0b1, < 2.52.0. Upgrade to 1.107.7 / 2.52.0 or later.
CVE-2026-107287 / GHSA-v36g-jcw9-x7cw · severity: medium · CVSS 6.5 · PyPI
Affected
pydantic-ai>= 1.77.0, < 1.107.7 → fixed in 1.107.7pydantic-ai>= 2.0.0b1, < 2.52.0 → fixed in 2.52.0
Details
Summary
Applications using Pydantic AI's local web-fetch tool can experience excessive CPU and memory use when it converts attacker-controlled HTML. An agent must fetch the affected page; provider-native web fetching is not affected.
Details
Nested block elements cause HTML-to-Markdown conversion to reprocess accumulated text at each level and can greatly expand the intermediate output. The response-body limit bounds downloaded bytes, while the returned-content limit is applied only after conversion. On current releases, conversion runs in a worker thread but can still consume substantial resources and delay other work in the process. Older releases performed conversion on the event loop.
Mitigation
Upgrade to a patched release of pydantic-ai or pydantic-ai-slim. If you cannot upgrade yet, avoid using local web fetching for attacker-controlled HTML.
Source: GHSA-v36g-jcw9-x7cw — GitHub Advisory Database (CC-BY-4.0).