Pydantic AI 是一个用于构建生成式 AI 应用和流程的 Python 代理框架。在版本 2.10.0 至 2.53.0 之间,通过 ConcurrencyLimitedModel 或 limit_model_concurrency 发起的流式请求可能会保留共享的并发配额(slots)。这是因为 anyio.CapacityLimiter 将已获取的配额与借用该配额的“任务”关联,而流式清理操作可能在另一个不同的任务中执行。因此,早期终止流、取消操作、消费者端异常,或者在使用 debounce_by=0.1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pydantic | pydantic-ai | >= 2.10.0, < 2.53.0 | - |
|
| pydantic | pydantic-ai-slim | >= 2.10.0, < 2.53.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107295 | 7.6 HIGH | `pydantic-ai-slim` web UI `/api/chat` accepts browser-simple cross-origin requests that ca |
| CVE-2026-107289 | 6.8 MEDIUM | Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv6 zone identifier (incomplete fix |
| CVE-2026-107287 | 6.5 MEDIUM | Pydantic AI: Excessive resource use when local web fetching converts nested HTML |
| CVE-2026-107290 | 6.5 MEDIUM | Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch` |
| CVE-2026-107294 | 6.5 MEDIUM | Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl |
| CVE-2026-107292 | 6.4 MEDIUM | Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): the local chat endpoint does not v |
| CVE-2026-107288 | 3.7 LOW | Pydantic AI: web_fetch_tool blocked_domains bypass via a hostname the resolver normalizes |
| CVE-2026-107291 | 2.3 LOW | Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans in |
| CVE-2026-107293 | 2.3 LOW | Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `incl |
No comments yet