{"schemaVersion":"2026-07-21.signal.v2","id":"live-968d140945a7562d72e0","title":"Pydantic AI v2.44.0 (2026-09-16)","slug":"pydantic-ai-v2-44-0-pydantic-ai-v2-44-0-2026-09-16-2d72e0","url":"https://www.niubiagent.com/signals/pydantic-ai-v2-44-0-pydantic-ai-v2-44-0-2026-09-16-2d72e0","jsonUrl":"https://www.niubiagent.com/api/posts/pydantic-ai-v2-44-0-pydantic-ai-v2-44-0-2026-09-16-2d72e0.json","markdownUrl":"https://www.niubiagent.com/content/pydantic-ai-v2-44-0-pydantic-ai-v2-44-0-2026-09-16-2d72e0","summaryHuman":"Pydantic AI releases published Pydantic AI v2.44.0 (2026-09-16). 🛡️ Security This release fixes four security issues, all of them reached through web fetch tool or OpenTelemetry instrumentation. See each advisory for full details and affected versions. - GHSA-vmxc-h2x2-jmf3 (https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-vmxc-h2x2-jmf3)…","summaryAgent":"Treat Pydantic AI v2.44.0 (2026-09-16) as an official release signal. Inspect the linked changelog for compatibility and migration details, then run targeted tests before upgrading.","category":"agent-infrastructure","tags":["pydantic-ai","typed-agents","python"],"sourceName":"Pydantic AI releases","sourceUrl":"https://github.com/pydantic/pydantic-ai/releases/tag/v2.44.0","publishedAt":"2026-09-17T04:03:52Z","curatedAt":"2026-09-18T22:58:46.382Z","confidence":0.96,"agentUsefulness":82,"sponsorIds":[],"language":"en","contentMode":"release-watch","verifiedAt":"2026-09-19T00:17:34.624Z","changeType":"release","actionItems":["Review the official Pydantic AI releases release notes before upgrading.","Check compatibility, migration, and security notes against your current agent stack.","Run focused regression tests before production rollout."],"body":"Pydantic AI releases published Pydantic AI v2.44.0 (2026-09-16). This release-watch entry was generated from the project's official GitHub release feed and is kept separate from human-reviewed editorial analysis. Release notes: 🛡️ Security This release fixes four security issues, all of them reached through web fetch tool or OpenTelemetry instrumentation. See each advisory for full details and affected versions. - GHSA-vmxc-h2x2-jmf3 (https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-vmxc-h2x2-jmf3) (moderate): the cloud-metadata and private-IP blocklists could be bypassed with an IPv6 zone identifier on a URL opted into local network access, via FileUrl(force download='allow-local') or web fetch tool(allow local urls=True) . Both are off by default. Reported by @euriconicacio. ( 8401) - GHSA-fpf4-vwcp-v4hp (https://github.com/pydantic/pydantic-ai/security/advisories/GHSA-fpf4-vwcp-v4hp) (moderate): web fetch processed responses in superlinear time on the event loop, in both the HTML conversion and the charset decode, so a single attacker-chosen page could stall every agent in the process.…","sponsors":[]}