Qeravio
Canonical AI event

Pydantic AI 2.52.0 fixes web_fetch CPU and memory issue.

The latest release addresses a moderate security flaw in web_fetch that could lead to excessive CPU and memory usage.

30 Sept 20261 verified claims1 sources1 observations
What happened

The official source reports this update: v2.52.0 (2026-09-29). 🛡️ Security This release fixes one security issue in web_fetch . See the advisory for full details and affected versions. GHSA-v36g-jcw9-x7cw (moderate): converting attacker-controlled HTML with deeply nested elements in the local web_fetch tool could consume excessive CPU and memory. Provider-native web fetching is not affected. Reported by @SounLabs . ( #8984 ) Patched in 2.52.0 (v2) and 1.107.7 (v1). 📦 Harness and CLAI 2 pydantic-ai-harness now lives in this repository and ships with every Pydantic AI release, so it jumps from 0.36.0 to 0.52.0 . pydantic-clai2 0.52.0 is its first release: uvx pydantic-clai2 .

Why it matters

This official update documents a development concerning v2.52.0 (2026-09-29). Its practical significance depends on the scope and evidence stated by the source.

What to watch next

Read the official source update and verify its stated scope, evidence and timing before acting on it.

Connected knowledge

Entities affected by this event

Continue this topic
Evidence trail

Sources behind the event