7.5

CVE-2026-107286

Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency can retain shared concurrency slots because anyio.CapacityLimiter associates an acquired slot with the borrowing task while streaming cleanup can run in a different task. Early stream termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can therefore leave capacity occupied, eventually preventing later requests that share the long-lived limiter from proceeding and causing a denial of service. Agent-level max_concurrency and non-streaming model requests are not affected. This issue is fixed in version 2.53.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerpydantic
≫
Produkt pydantic-ai
Version >= 2.10.0, < 2.53.0
Status affected
Herstellerpydantic
≫
Produkt pydantic-ai-slim
Version >= 2.10.0, < 2.53.0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.371
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-6fqq-452j-qhrp
https://github.com/pydantic/pydantic-ai/pull/9478
https://github.com/pydantic/pydantic-ai/commit/453f19feeb7ab1d789f9393b1723c6a73b3d77b2
https://github.com/pydantic/pydantic-ai/releases/tag/v2.53.0