CVE-2026-101098
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X
Summary
A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ag-ui-protocol | ag-ui | 2026-09-23 | affected |
Weaknesses
- CWE-400: Resource Consumption
- CWE-404: Denial of Service
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://vuldb.com/vuln/410973
- https://vuldb.com/vuln/410973/cti
- https://vuldb.com/cve/CVE-2026-101098
- https://vuldb.com/submit/934960
- https://github.com/ag-ui-protocol/ag-ui/issues/2441
- https://github.com/ag-ui-protocol/ag-ui/pull/2671
- https://github.com/ag-ui-protocol/ag-ui/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.