Pydantic-AI 2.53.0 fixes a concurrency limiter that blocked streamed requests, and adds ToolCallJudge and a SystemOneModel endpoint
Pydantic-AI 2.53.0 patches a high-severity bug where a streamed request through ConcurrencyLimitedModel could keep its slot after an early exit, and adds ToolCallJudge, a SystemOneModel for decision models, and managed subagents in CLAI2.
Image: Pydantic
Why it mattersA team running the Pydantic-AI agent framework with concurrency limits should upgrade now, because the old limiter could leave every request behind a stuck slot once a stream exited early.
A team running Pydantic-AI's concurrency limiter with streamed requests was quietly running a limiter that could stop releasing slots. Version 2.53.0 shipped on 1 October 2026 and patches that bug under advisory GHSA-6fqq-452j-qhrp, which the maintainers graded high severity.
The bug lives in ConcurrencyLimitedModel and limit_model_concurrency. According to the release notes, a streamed request could keep its concurrency slot "when the slot was released on a different task than the one that acquired it", after an early exit where the consumer stopped iterating, raised, or was cancelled, and also after fully consuming stream_text() with its default debouncing. The maintainers write that "repeated streams could then block every request sharing the limiter". Agent-level max_concurrency and non-streaming requests are not affected, and v1 is not affected either.
The behavioural change that comes with the fix
The release notes say the fix also changes how limiters are shared. A model wrapper now raises UserError when it shares a limiter with the agent making the request or with an enclosing model wrapper. ConcurrencyLimiter.acquire() takes a slot on every call, even on the same task. A custom AbstractConcurrencyLimiter must allow release() from another task. Pydantic reported @lche511 for the private disclosure.
New capabilities in the same release
The release notes list several additions that are not security fixes. ToolCallJudge assesses tool calls before execution. SystemOneModel runs decision models such as CLM and Laya over the /v1/systemone API. CLAI2, the project's command-line agent, picks up managed subagents with built-in Claude and Codex agent definitions in Harness, a repair_messages pipeline to repair message history, and a Codex-only /fast command. The CLAI2 plugin system is now a set of declarative Plugin subclasses modelled on AbstractCapability, with built-in plugins for PostHog, Grain, Linear, Herdr and an observability plugin that renames the previous logfire plugin.
The release notes describe what each new piece does, and that is the material this item is reporting. Pydantic did not publish a benchmark for ToolCallJudge or SystemOneModel in these notes, so neither is quoted as faster or cheaper than any alternative.
The team that should read this today is a team already on Pydantic-AI with a concurrency limiter in production and streamed responses in the mix. The upgrade path is a version bump from 2.52.0, and the release records 26 bug fixes in addition to the advisory, including a Temporal activity schema fix, a BubblewrapSandbox file-escape fix, and a UnexpectedModelBehavior raise when two function tool calls share a tool_call_id.
Source
- Primary source: Pydantic-AI v2.53.0 release notes, 1 October 2026
- Security advisory: GHSA-6fqq-452j-qhrp
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.
