Pydantic AI: Excessive resource use when local web fetching converts nested HTML
🔗 CVE IDs covered (1)
📋 Description
Summary
Applications using Pydantic AI's local web-fetch tool can experience excessive CPU and memory use when it converts attacker-controlled HTML. An agent must fetch the affected page; provider-native web fetching is not affected.
Details
Nested block elements cause HTML-to-Markdown conversion to reprocess accumulated text at each level and can greatly expand the intermediate output. The response-body limit bounds downloaded bytes, while the returned-content limit is applied only after conversion. On current releases, conversion runs in a worker thread but can still consume substantial resources and delay other work in the process. Older releases performed conversion on the event loop.
Mitigation
Upgrade to a patched release of pydantic-ai or pydantic-ai-slim. If you cannot upgrade yet, avoid using local web fetching for attacker-controlled HTML.
🎯 Affected products4
- pip/pydantic-ai:>= 1.77.0, < 1.107.7
- pip/pydantic-ai:>= 2.0.0b1, < 2.52.0
- pip/pydantic-ai-slim:>= 1.77.0, < 1.107.7
- pip/pydantic-ai-slim:>= 2.0.0b1, < 2.52.0
🔗 References (8)
- https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-v36g-jcw9-x7cw
- https://github.com/pydantic/pydantic-ai/pull/8984
- https://github.com/pydantic/pydantic-ai/pull/8985
- https://github.com/pydantic/pydantic-ai/commit/2b247add4950bef61d352e7ca8aefbd20539180c
- https://github.com/pydantic/pydantic-ai/commit/2fd38792693da00a3ca5412aeffb436787af3545
- https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.7
- https://github.com/pydantic/pydantic-ai/releases/tag/v2.52.0
- https://github.com/advisories/GHSA-v36g-jcw9-x7cw