{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0.3.4"
              },
              {
                "fixed": "1.107.6"
              },
              {
                "introduced": "2.0.0b1"
              },
              {
                "fixed": "2.44.0"
              }
            ],
            "source": "AFFECTED_FIELD"
          },
          "events": [
            {
              "introduced": "a341e566274f8b82d15a8a2f7933fe732752cc5e"
            },
            {
              "fixed": "7ee27e38ab2e525ca60ff1a25d16413ff989fd79"
            },
            {
              "introduced": "6001a4549018ad5509f2c11ed6c38d2385159506"
            },
            {
              "fixed": "9fdabb4b2afb54ff7deb9013f6b43971324d9181"
            }
          ],
          "repo": "https://github.com/pydantic/pydantic-ai",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-4x9p-g9wm-8q7f"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-212",
      "CWE-532"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107291.json"
  },
  "details": "Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.6 and 2.44.0, OpenTelemetry instrumentation configured with InstrumentationSettings(include_content=False) can still export sensitive agent content through exception.message and exception.stacktrace events, error status descriptions, and model_request_parameters containing instructions or the prompted_output_template. The exposed data is available to readers of the configured telemetry backend and can include tool feedback, provider error bodies, runtime instructions, and structured-output templates even though message attributes are redacted. This issue does not grant new access to agent data, and deployments that do not use include_content=False are not affected by the setting bypass. This issue is fixed in versions 1.107.6 and 2.44.0.",
  "id": "CVE-2026-107291",
  "modified": "2026-10-09T02:30:47.037543342Z",
  "published": "2026-10-08T16:22:51.763Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107291.json"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pydantic/pydantic-ai/commit/4e013c51a50659aba2adf7853bfb22bb77f6a518"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pydantic/pydantic-ai/commit/6b14c74cb281f899a2ae4fae5327111e33f60771"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pydantic/pydantic-ai/commit/7ee27e38ab2e525ca60ff1a25d16413ff989fd79"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pydantic/pydantic-ai/commit/963dec5f70d6f558997fc259356c0090cc5ea487"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pydantic/pydantic-ai/commit/de4e61515327bd80a19cd8552001c30933e6acc3"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pydantic/pydantic-ai/pull/8403"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pydantic/pydantic-ai/pull/8404"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pydantic/pydantic-ai/pull/8408"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pydantic/pydantic-ai/pull/8428"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pydantic/pydantic-ai/pull/8429"
    },
    {
      "type": "WEB",
      "url": "https://github.com/pydantic/pydantic-ai/releases/tag/v1.107.6"
    },
    {
      "type": "WEB",
      "url": "https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-4x9p-g9wm-8q7f"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107291"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Pydantic AI OpenTelemetry instrumentation: exception events on tool and agent run spans include content when `include_content=False`"
}