Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6fqq-452j-qhrp | Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early |
Thu, 08 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pydantic
Pydantic pydantic-ai |
|
| Vendors & Products |
Pydantic
Pydantic pydantic-ai |
Thu, 08 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency can retain shared concurrency slots because anyio.CapacityLimiter associates an acquired slot with the borrowing task while streaming cleanup can run in a different task. Early stream termination, cancellation, consumer exceptions, or complete stream_text() consumption with debounce_by=0.1 can therefore leave capacity occupied, eventually preventing later requests that share the long-lived limiter from proceeding and causing a denial of service. Agent-level max_concurrency and non-streaming model requests are not affected. This issue is fixed in version 2.53.0. | |
| Title | Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early | |
| Weaknesses | CWE-772 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T17:27:24.185Z
Reserved: 2026-10-07T15:53:23.586Z
Link: CVE-2026-107286
Updated: 2026-10-08T17:27:17.682Z
Status : Awaiting Analysis
Published: 2026-10-08T15:17:40.753
Modified: 2026-10-08T20:35:31.200
Link: CVE-2026-107286
No data.
OpenCVE Enrichment
Updated: 2026-10-08T20:00:02Z
-
CWE-772
Missing Release of Resource after Effective Lifetime
Github GHSA