CVE-2026-107295
- EPSS 0.16%
- Veröffentlicht 08.10.2026 17:02:36
- Zuletzt bearbeitet 08.10.2026 20:35:31
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A website...
CVE-2026-107294
- EPSS 0.43%
- Veröffentlicht 08.10.2026 16:59:25
- Zuletzt bearbeitet 09.10.2026 16:17:21
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileUrl media downloads buffer the complete HTTP respons...
CVE-2026-107293
- EPSS 0.34%
- Veröffentlicht 08.10.2026 16:57:24
- Zuletzt bearbeitet 08.10.2026 20:35:31
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.4 and 2.27.1, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can export retry pro...
CVE-2026-107292
- EPSS 0.13%
- Veröffentlicht 08.10.2026 16:26:48
- Zuletzt bearbeitet 08.10.2026 20:35:31
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 2.30.0, the Agent.to_web() and clai web development chat server does not validate the Host header, allowing a website visited by a d...
CVE-2026-107291
- EPSS 0.39%
- Veröffentlicht 08.10.2026 16:22:51
- Zuletzt bearbeitet 08.10.2026 20:35:31
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.6 and 2.44.0, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can still export sen...
CVE-2026-107290
- EPSS 0.42%
- Veröffentlicht 08.10.2026 16:09:04
- Zuletzt bearbeitet 09.10.2026 16:17:21
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback process server-controlled responses with quadratic titl...
CVE-2026-107289
- EPSS 0.33%
- Veröffentlicht 08.10.2026 15:20:18
- Zuletzt bearbeitet 08.10.2026 20:35:31
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.56.0 until 1.107.6 and 2.44.0, applications that opt attacker-influenced URLs into local network access through FileUrl with force_download='al...
CVE-2026-107288
- EPSS 0.38%
- Veröffentlicht 08.10.2026 15:18:40
- Zuletzt bearbeitet 08.10.2026 20:35:31
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.6 and 2.44.0, the local web_fetch_tool and the WebFetch local fallback compare blocked_domains entries with a URL hostname bef...
CVE-2026-107287
- EPSS 0.28%
- Veröffentlicht 08.10.2026 15:15:05
- Zuletzt bearbeitet 08.10.2026 21:05:00
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.7 and 2.52.0, the local web_fetch_tool and the WebFetch local fallback can consume excessive CPU and memory during HTML-to-Mar...
CVE-2026-107286
- EPSS 0.45%
- Veröffentlicht 08.10.2026 15:12:26
- Zuletzt bearbeitet 08.10.2026 20:35:31
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency can retain shared concurrency slots becaus...