CVE-2026-107286: Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early

Published Oct 8, 2026
·
Updated

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limitmodelconcurrency can retain shared concurrency slots because anyio.CapacityLimiter associates an acquired slot with the borrowing task while streaming cleanup can run in a different task. Early stream termination, cancellation, consumer exceptions, or complete streamtext() consumption with debounceby=0.1 can therefore leave capacity occupied, eventually preventing later requests that share the long-lived limiter from proceeding and causing a denial of service. Agent-level maxconcurrency and non-streaming model requests are not affected. This issue is fixed in version 2.53.0.

Affected Software

1 affected component
pypi/pydantic-ai>=2.10.0<2.53.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Pydantic AI to a version that resolves this vulnerability.

    Fixed in 2.53.0

Event History

Oct 8, 2026
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this denial-of-service condition?

Deployments using Pydantic AI versions 2.10.0 through versions before 2.53.0 are affected when streamed requests use ConcurrencyLimitedModel or limit_model_concurrency with a shared, long-lived limiter. Agent-level max_concurrency and non-streaming model requests are not affected.

2

What request behavior can trigger exhaustion of concurrency slots?

A streamed request can retain its slot when it ends early due to cancellation, consumer exceptions, or early stream termination. Complete stream_text() consumption can also retain a slot when debounce_by is set to 0.1.

3

What is the practical impact once slots are retained?

Retained slots consume the shared limiter's available capacity. Over time, later requests sharing that long-lived limiter may be unable to proceed, causing denial of service.

4

What remediation is available?

Upgrade Pydantic AI to version 2.53.0, which fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203