CVE-2026-107286: Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limitmodelconcurrency can retain shared concurrency slots because anyio.CapacityLimiter associates an acquired slot with the borrowing task while streaming cleanup can run in a different task. Early stream termination, cancellation, consumer exceptions, or complete streamtext() consumption with debounceby=0.1 can therefore leave capacity occupied, eventually preventing later requests that share the long-lived limiter from proceeding and causing a denial of service. Agent-level maxconcurrency and non-streaming model requests are not affected. This issue is fixed in version 2.53.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pydantic AIto a version that resolves this vulnerability.Fixed in 2.53.0
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service condition?
Deployments using Pydantic AI versions 2.10.0 through versions before 2.53.0 are affected when streamed requests use ConcurrencyLimitedModel or limit_model_concurrency with a shared, long-lived limiter. Agent-level max_concurrency and non-streaming model requests are not affected.
What request behavior can trigger exhaustion of concurrency slots?
A streamed request can retain its slot when it ends early due to cancellation, consumer exceptions, or early stream termination. Complete stream_text() consumption can also retain a slot when debounce_by is set to 0.1.
What is the practical impact once slots are retained?
Retained slots consume the shared limiter's available capacity. Over time, later requests sharing that long-lived limiter may be unable to proceed, causing denial of service.
What remediation is available?
Upgrade Pydantic AI to version 2.53.0, which fixes the issue.