<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 19:33:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-290883</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290883</link>
      <description>EUVD-2026-290883</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290883</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40115</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40115</link>
      <description>&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire HTTP request body into memory based on the client-supplied Content-Length header with no upper bound. Combined with authentication being disabled by default (no token configured), any local process can send arbitrarily large POST requests to exhaust server memory and cause a denial of service. The Starlette-based server (serve.py) has RequestSizeLimitMiddleware with a 10MB limit, but the WSGI server lacks any equivalent protection. This vulnerability is fixed in 4.5.128.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire HTTP request body into memory based on the client-supplied Content-Length header with no upper bound. Combined with authentication being disabled by default (no token configured), any local process can send arbitrarily large POST requests to exhaust server memory and cause a denial of service. The Starlette-based server (serve.py) has RequestSizeLimitMiddleware with a 10MB limit, but the WSGI server lacks any equivalent protection. This vulnerability is fixed in 4.5.128.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40115</guid>
    </item>
    <item>
      <title>GHSA-2xgv-5cv2-47vv — PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2xgv-5cv2-47vv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The WSGI-based recipe registry server (`server.py`) reads the entire HTTP request body into memory based on the client-supplied `Content-Length` header with no upper bound. Combined with authentication being disabled by default (no token configured), any local process can send arbitrarily large POST requests to exhaust server memory and cause a denial of service. The Starlette-based server (`serve.py`) has `RequestSizeLimitMiddleware` with a 10MB limit, but the WSGI server lacks any equivalent protection.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable code path in `src/praisonai/praisonai/recipe/server.py`:&lt;/p&gt;
&lt;p&gt;**1. No size limit on body read (line 551-555):**
```python
content_length = int(environ.get(&amp;#34;CONTENT_LENGTH&amp;#34;, 0))
body = environ[&amp;#34;wsgi.input&amp;#34;].read(content_length) if content_length &amp;gt; 0 else b&amp;#34;&amp;#34;
```&lt;/p&gt;
&lt;p&gt;The `content_length` is taken directly from the HTTP header with no maximum check. The entire body is read into a single `bytes` object in memory.&lt;/p&gt;
&lt;p&gt;**2. Second in-memory copy via multipart parsing (line 169-172):**
```python
result = {&amp;#34;fields&amp;#34;: {}, &amp;#34;files&amp;#34;: {}}
boundary_bytes = f&amp;#34;--{boundary}&amp;#34;.encode()
parts = body.split(boundary_bytes)
```&lt;/p&gt;
&lt;p&gt;The `_parse_multipart` method splits the already-buffered body and stores file contents in a dict, creating additional in-memory copies.&lt;/p&gt;
&lt;p&gt;**3. Third copy to temp file (line 420-421):**
```python
with tempfile.NamedTemporaryFile(suffix=&amp;#34;.praison&amp;#34;, delete=False) as tmp:
    tmp.write(bundle_content)
```&lt;/p&gt;
&lt;p&gt;The bundle content is then written to dis…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The WSGI-based recipe registry server (`server.py`) reads the entire HTTP request body into memory based on the client-supplied `Content-Length` header with no upper bound. Combined with authentication being disabled by default (no token configured), any local process can send arbitrarily large POST requests to exhaust server memory and cause a denial of service. The Starlette-based server (`serve.py`) has `RequestSizeLimitMiddleware` with a 10MB limit, but the WSGI server lacks any equivalent protection.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable code path in `src/praisonai/praisonai/recipe/server.py`:&lt;/p&gt;
&lt;p&gt;**1. No size limit on body read (line 551-555):**
```python
content_length = int(environ.get(&amp;#34;CONTENT_LENGTH&amp;#34;, 0))
body = environ[&amp;#34;wsgi.input&amp;#34;].read(content_length) if content_length &amp;gt; 0 else b&amp;#34;&amp;#34;
```&lt;/p&gt;
&lt;p&gt;The `content_length` is taken directly from the HTTP header with no maximum check. The entire body is read into a single `bytes` object in memory.&lt;/p&gt;
&lt;p&gt;**2. Second in-memory copy via multipart parsing (line 169-172):**
```python
result = {&amp;#34;fields&amp;#34;: {}, &amp;#34;files&amp;#34;: {}}
boundary_bytes = f&amp;#34;--{boundary}&amp;#34;.encode()
parts = body.split(boundary_bytes)
```&lt;/p&gt;
&lt;p&gt;The `_parse_multipart` method splits the already-buffered body and stores file contents in a dict, creating additional in-memory copies.&lt;/p&gt;
&lt;p&gt;**3. Third copy to temp file (line 420-421):**
```python
with tempfile.NamedTemporaryFile(suffix=&amp;#34;.praison&amp;#34;, delete=False) as tmp:
    tmp.write(bundle_content)
```&lt;/p&gt;
&lt;p&gt;The bundle content is then written to dis…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2xgv-5cv2-47vv</guid>
    </item>
    <item>
      <title>PYSEC-2026-2896 — PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2896</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The WSGI-based recipe registry server (`server.py`) reads the entire HTTP request body into memory based on the client-supplied `Content-Length` header with no upper bound. Combined with authentication being disabled by default (no token configured), any local process can send arbitrarily large POST requests to exhaust server memory and cause a denial of service. The Starlette-based server (`serve.py`) has `RequestSizeLimitMiddleware` with a 10MB limit, but the WSGI server lacks any equivalent protection.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable code path in `src/praisonai/praisonai/recipe/server.py`:&lt;/p&gt;
&lt;p&gt;**1. No size limit on body read (line 551-555):**
```python
content_length = int(environ.get(&amp;#34;CONTENT_LENGTH&amp;#34;, 0))
body = environ[&amp;#34;wsgi.input&amp;#34;].read(content_length) if content_length &amp;gt; 0 else b&amp;#34;&amp;#34;
```&lt;/p&gt;
&lt;p&gt;The `content_length` is taken directly from the HTTP header with no maximum check. The entire body is read into a single `bytes` object in memory.&lt;/p&gt;
&lt;p&gt;**2. Second in-memory copy via multipart parsing (line 169-172):**
```python
result = {&amp;#34;fields&amp;#34;: {}, &amp;#34;files&amp;#34;: {}}
boundary_bytes = f&amp;#34;--{boundary}&amp;#34;.encode()
parts = body.split(boundary_bytes)
```&lt;/p&gt;
&lt;p&gt;The `_parse_multipart` method splits the already-buffered body and stores file contents in a dict, creating additional in-memory copies.&lt;/p&gt;
&lt;p&gt;**3. Third copy to temp file (line 420-421):**
```python
with tempfile.NamedTemporaryFile(suffix=&amp;#34;.praison&amp;#34;, delete=False) as tmp:
    tmp.write(bundle_content)
```&lt;/p&gt;
&lt;p&gt;The bundle content is then written to dis…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The WSGI-based recipe registry server (`server.py`) reads the entire HTTP request body into memory based on the client-supplied `Content-Length` header with no upper bound. Combined with authentication being disabled by default (no token configured), any local process can send arbitrarily large POST requests to exhaust server memory and cause a denial of service. The Starlette-based server (`serve.py`) has `RequestSizeLimitMiddleware` with a 10MB limit, but the WSGI server lacks any equivalent protection.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable code path in `src/praisonai/praisonai/recipe/server.py`:&lt;/p&gt;
&lt;p&gt;**1. No size limit on body read (line 551-555):**
```python
content_length = int(environ.get(&amp;#34;CONTENT_LENGTH&amp;#34;, 0))
body = environ[&amp;#34;wsgi.input&amp;#34;].read(content_length) if content_length &amp;gt; 0 else b&amp;#34;&amp;#34;
```&lt;/p&gt;
&lt;p&gt;The `content_length` is taken directly from the HTTP header with no maximum check. The entire body is read into a single `bytes` object in memory.&lt;/p&gt;
&lt;p&gt;**2. Second in-memory copy via multipart parsing (line 169-172):**
```python
result = {&amp;#34;fields&amp;#34;: {}, &amp;#34;files&amp;#34;: {}}
boundary_bytes = f&amp;#34;--{boundary}&amp;#34;.encode()
parts = body.split(boundary_bytes)
```&lt;/p&gt;
&lt;p&gt;The `_parse_multipart` method splits the already-buffered body and stores file contents in a dict, creating additional in-memory copies.&lt;/p&gt;
&lt;p&gt;**3. Third copy to temp file (line 420-421):**
```python
with tempfile.NamedTemporaryFile(suffix=&amp;#34;.praison&amp;#34;, delete=False) as tmp:
    tmp.write(bundle_content)
```&lt;/p&gt;
&lt;p&gt;The bundle content is then written to dis…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2896</guid>
    </item>
  </channel>
</rss>
