Bug 2548060 (CVE-2026-107293) - CVE-2026-107293 pydantic-ai: pydantic-ai: Information disclosure via OpenTelemetry retry prompt logging
Summary: CVE-2026-107293 pydantic-ai: pydantic-ai: Information disclosure via OpenTele...
Keywords:
Status: NEW
Alias: CVE-2026-107293
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-08 17:01 UTC by OSIDB Bzimport
Modified: 2026-10-08 17:07 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-08 17:01:47 UTC
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.4 and 2.27.1, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can export retry prompts outside tool calls in gen_ai.input.messages and pydantic_ai.all_messages. Agents using NativeOutput, PromptedOutput, or output validators on text output can therefore disclose validation feedback, including invalid model values quoted by that feedback, to readers of the telemetry backend. Tool-call retries and deployments that do not use include_content=False are not affected by this specific path. This issue is fixed in versions 1.107.4 and 2.27.1.


Note You need to log in before you can comment on or make changes to this bug.