GHSA-6fqq-452j-qhrp: High severity pip/pydantic-ai-slim vulnerability

Published Oct 8, 2026
·
Updated

This issue was posted by Codex Desktop using gpt-6.1-sol on behalf of David.

Summary

Applications that wrap a model with ConcurrencyLimitedModel or limitmodelconcurrency can permanently lose shared concurrency capacity when a streamed request releases its slot from a different task than the one that acquired it. This can happen when a stream ends early, and also when a stream is fully consumed using the default streamtext() debouncing.

In an application that exposes an affected streaming endpoint to network clients and shares a long-lived model limiter across requests, a client can repeatedly start a stream and disconnect. The completed requests retain their slots, eventually preventing subsequent requests that share the limiter from proceeding.

Agent-level maxconcurrency and non-streaming model requests are not affected by this defect.

Details

The built-in limiter uses anyio.CapacityLimiter, which associates each acquired slot with its borrowing task. Pydantic AI's streaming lifecycle can acquire the slot on the task consuming the stream and run cleanup on another internal task. The limiter rejects that release, so the slot remains occupied even after the request has ended. Cleanup can raise a RuntimeError; a later request on the borrowing task can also fail because that task still holds a slot.

Early termination includes stopping iteration, a consumer exception, and cancellation. Fully consuming streamtext() with its default debounceby=0.1 can also reach the cross-task release path. Fully consumed streams must therefore not be assumed safe.

Mitigation

Upgrade to a patched release of pydantic-ai or pydantic-ai-slim. If you cannot upgrade yet, use the agent-level maxconcurrency setting instead of a concurrency-limited model, or avoid streaming runs through a concurrency-limited model.

Affected Software

2 affected componentsFixes available
pip/pydantic-ai-slim>=2.10.0<2.53.0
2.53.0
pip/pydantic-ai>=2.10.0<2.53.0
2.53.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/pydantic-ai-slim to a version that resolves this vulnerability.

    Fixed in 2.53.0
  2. Upgrade

    Upgrade pip/pydantic-ai to a version that resolves this vulnerability.

    Fixed in 2.53.0
  3. Configuration

    Use the agent-level max_concurrency setting instead of wrapping the model with ConcurrencyLimitedModel or limit_model_concurrency.

    Pydantic AI agent max_concurrency = agent-level max_concurrency
  4. Compensating control

    Avoid streaming runs through a concurrency-limited model until the affected pydantic-ai or pydantic-ai-slim component is upgraded.

Event History

Oct 8, 2026
Advisory Published
via GitHub·07:42 PM
Data Sourced
via GitHub·07:42 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are realistically exposed to service disruption?

Applications are exposed when they provide an affected streaming endpoint to network clients and use a long-lived shared limiter created with ConcurrencyLimitedModel or limit_model_concurrency. Agent-level max_concurrency and non-streaming model requests are not affected.

2

What must an attacker do to exhaust capacity?

An unauthenticated network client can repeatedly begin streamed requests and disconnect. Each affected request can retain a shared concurrency slot, eventually preventing later requests using that limiter from proceeding.

3

Does a stream have to be abandoned early for this to occur?

No. Early stream termination can trigger the issue, but a stream fully consumed through the default stream_text() debouncing behavior can also release its slot from a different task and leave capacity occupied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203