GHSA-v36g-jcw9-x7cw: Medium severity pip/pydantic-ai-slim vulnerability
Summary
Applications using Pydantic AI's local web-fetch tool can experience excessive CPU and memory use when it converts attacker-controlled HTML. An agent must fetch the affected page; provider-native web fetching is not affected.
Details
Nested block elements cause HTML-to-Markdown conversion to reprocess accumulated text at each level and can greatly expand the intermediate output. The response-body limit bounds downloaded bytes, while the returned-content limit is applied only after conversion. On current releases, conversion runs in a worker thread but can still consume substantial resources and delay other work in the process. Older releases performed conversion on the event loop.
Mitigation
Upgrade to a patched release of pydantic-ai or pydantic-ai-slim. If you cannot upgrade yet, avoid using local web fetching for attacker-controlled HTML.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pydantic-ai-slimto a version that resolves this vulnerability.Fixed in 2.52.0 - Upgrade
Upgrade
pip/pydantic-ai-slimto a version that resolves this vulnerability.Fixed in 1.107.7 - Upgrade
Upgrade
pip/pydantic-aito a version that resolves this vulnerability.Fixed in 2.52.0 - Upgrade
Upgrade
pip/pydantic-aito a version that resolves this vulnerability.Fixed in 1.107.7 - Compensating control
Avoid using Pydantic AI's local web-fetch tool for attacker-controlled HTML until upgrading.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Applications are exposed when they use Pydantic AI's local web-fetch tool and an agent fetches attacker-controlled HTML. Provider-native web fetching is not affected.
What must an attacker do to trigger the resource exhaustion?
An attacker needs to cause the agent to fetch a crafted HTML page containing deeply nested block elements. The HTML-to-Markdown conversion repeatedly processes accumulated text, which can greatly expand intermediate output and consume CPU and memory.
Do response or returned-content limits prevent exploitation?
Not necessarily. The response-body limit applies to downloaded bytes, while the returned-content limit is enforced only after HTML-to-Markdown conversion has already occurred.
What can be done before a patched release is deployed?
Avoid local web fetching for attacker-controlled HTML. Upgrading pydantic-ai or pydantic-ai-slim to a patched release is the recommended mitigation.
How can the operational impact differ between releases?
Current releases perform conversion in a worker thread, but it can still consume substantial process resources and delay other work. Older releases performed conversion on the event loop.