Search

Find a vulnerability

Search criteria

    20 vulnerabilities by ag-ui-protocol

    CVE-2026-101101 (GCVE-0-2026-101101)

    Vulnerability from nvd – Published: 2026-09-28 17:45 – Updated: 2026-09-28 18:13 X_Open Source
    VLAI
    Title
    ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception
    Summary
    A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitation of the attack is possible. Upgrading to version 2026-09-08 is capable of addressing this issue. The identifier of the patch is 30f8c794d5b73df5c610153043db502b2cc106cc. Upgrading the affected component is recommended.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 18:13 UTC
    CWE
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 2026-09-07
    Unaffected: 2026-09-08
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101101",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T18:13:26.343570Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T18:13:33.954Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Middleware"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "2026-09-07"
                },
                {
                  "status": "unaffected",
                  "version": "2026-09-08"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitation of the attack is possible. Upgrading to version 2026-09-08 is capable of addressing this issue. The identifier of the patch is 30f8c794d5b73df5c610153043db502b2cc106cc. Upgrading the affected component is recommended."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-248",
                  "description": "Uncaught Exception",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T17:45:11.629Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-410976 | ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/410976"
            },
            {
              "name": "VDB-410976 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/410976/cti"
            },
            {
              "name": "CVE-2026-101101 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-101101"
            },
            {
              "name": "Submit #934981 | ag-ui-protocol ag-ui v1.0 CWE-248",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934981"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2444"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2493"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/commit/30f8c794d5b73df5c610153043db502b2cc106cc"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/releases/tag/release/2026-09-08"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-08T00:00:00.000Z",
              "value": "Countermeasure disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-28T04:59:01.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-101101",
        "datePublished": "2026-09-28T17:45:11.629Z",
        "dateReserved": "2026-09-28T02:53:41.099Z",
        "dateUpdated": "2026-09-28T18:13:33.954Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101100 (GCVE-0-2026-101100)

    Vulnerability from nvd – Published: 2026-09-28 17:30 – Updated: 2026-09-28 17:47 X_Open Source
    VLAI
    Title
    ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup
    Summary
    A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddleware of the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts of the component Middleware. Executing a manipulation can lead to incomplete cleanup. The attack may be launched remotely. Upgrading to version 2026-09-08 is able to resolve this issue. This patch is called c346119fe870b70f5c19738ee5119f3e1456e59d. It is suggested to upgrade the affected component.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 17:47 UTC
    CWE
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 2026-09-07
    Unaffected: 2026-09-08
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101100",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T17:47:46.613540Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T17:47:55.078Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Middleware"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "2026-09-07"
                },
                {
                  "status": "unaffected",
                  "version": "2026-09-08"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddleware of the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts of the component Middleware. Executing a manipulation can lead to incomplete cleanup. The attack may be launched remotely. Upgrading to version 2026-09-08 is able to resolve this issue. This patch is called c346119fe870b70f5c19738ee5119f3e1456e59d. It is suggested to upgrade the affected component."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5.5,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-459",
                  "description": "Incomplete Cleanup",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T17:30:15.988Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-410975 | ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/410975"
            },
            {
              "name": "VDB-410975 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/410975/cti"
            },
            {
              "name": "CVE-2026-101100 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-101100"
            },
            {
              "name": "Submit #934980 | ag-ui-protocol ag-ui v1.0 CWE-459",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934980"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2443"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2494"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/commit/c346119fe870b70f5c19738ee5119f3e1456e59d"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/releases/tag/release/2026-09-08"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-08T00:00:00.000Z",
              "value": "Countermeasure disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-28T04:58:57.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-101100",
        "datePublished": "2026-09-28T17:30:15.988Z",
        "dateReserved": "2026-09-28T02:53:37.761Z",
        "dateUpdated": "2026-09-28T17:47:55.078Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101099 (GCVE-0-2026-101099)

    Vulnerability from nvd – Published: 2026-09-28 17:15 – Updated: 2026-10-01 14:37
    VLAI
    Title
    ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition
    Summary
    A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. Performing a manipulation results in handling of exceptional conditions. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:37 UTC
    CWE
    • CWE-755 - Handling of Exceptional Conditions
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 2026-09-23
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101099",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:37:44.354460Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:37:54.433Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Kotlin Community SDK"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "2026-09-23"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. Performing a manipulation results in handling of exceptional conditions. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:ND/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-755",
                  "description": "Handling of Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T17:15:15.683Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-410974 | ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/410974"
            },
            {
              "name": "VDB-410974 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/410974/cti"
            },
            {
              "name": "CVE-2026-101099 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-101099"
            },
            {
              "name": "Submit #934974 | ag-ui-protocol ag-ui v1.0 CWE-755",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934974"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2442"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2657"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-28T04:58:51.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-101099",
        "datePublished": "2026-09-28T17:15:15.683Z",
        "dateReserved": "2026-09-28T02:53:34.487Z",
        "dateUpdated": "2026-10-01T14:37:54.433Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101098 (GCVE-0-2026-101098)

    Vulnerability from nvd – Published: 2026-09-28 17:00 – Updated: 2026-09-28 17:48
    VLAI
    Title
    ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption
    Summary
    A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 17:48 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 2026-09-23
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101098",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T17:48:04.263858Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T17:48:21.413Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "HTTP Handler"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "2026-09-23"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:ND/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-404",
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T17:00:16.182Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-410973 | ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/410973"
            },
            {
              "name": "VDB-410973 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/410973/cti"
            },
            {
              "name": "CVE-2026-101098 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-101098"
            },
            {
              "name": "Submit #934960 | ag-ui-protocol ag-ui v1.0 CWE-400",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934960"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2441"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2671"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-28T04:58:47.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-101098",
        "datePublished": "2026-09-28T17:00:16.182Z",
        "dateReserved": "2026-09-28T02:53:30.772Z",
        "dateUpdated": "2026-09-28T17:48:21.413Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92363 (GCVE-0-2026-92363)

    Vulnerability from nvd – Published: 2026-09-16 13:30 – Updated: 2026-09-18 17:49 X_Open Source
    VLAI
    Title
    ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption
    Summary
    A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. This patch is called ab6e0bc298996caac2b4b0b3ec0bd8d32a15a186. Applying a patch is advised to resolve this issue.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 17:49 UTC
    CWE
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 1.0
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92363",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T17:49:29.298534Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T17:49:43.680Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "JSON Parser"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. This patch is called ab6e0bc298996caac2b4b0b3ec0bd8d32a15a186. Applying a patch is advised to resolve this issue."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-404",
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:30:10.476Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-405449 | ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/405449"
            },
            {
              "name": "VDB-405449 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/405449/cti"
            },
            {
              "name": "CVE-2026-92363 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92363"
            },
            {
              "name": "Submit #934957 | ag-ui-protocol ag-ui v1.0 CWE-400",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934957"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2440"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2501"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/commit/ab6e0bc298996caac2b4b0b3ec0bd8d32a15a186"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-16T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-16T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-16T07:41:38.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92363",
        "datePublished": "2026-09-16T13:30:10.476Z",
        "dateReserved": "2026-09-16T05:36:15.071Z",
        "dateUpdated": "2026-09-18T17:49:43.680Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92362 (GCVE-0-2026-92362)

    Vulnerability from nvd – Published: 2026-09-16 13:15 – Updated: 2026-09-16 15:50
    VLAI
    Title
    ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption
    Summary
    A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a manipulation results in resource consumption. The attack is possible to be carried out remotely. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 15:50 UTC
    CWE
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 1.0
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92362",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T15:50:38.770449Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T15:50:48.246Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "SSE Frame Parser"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a manipulation results in resource consumption. The attack is possible to be carried out remotely. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-404",
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:15:10.426Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-405448 | ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/405448"
            },
            {
              "name": "VDB-405448 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/405448/cti"
            },
            {
              "name": "CVE-2026-92362 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92362"
            },
            {
              "name": "Submit #934956 | ag-ui-protocol ag-ui v1.0 CWE-400",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934956"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2439"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2500"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-16T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-16T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-16T07:41:35.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92362",
        "datePublished": "2026-09-16T13:15:10.426Z",
        "dateReserved": "2026-09-16T05:36:11.812Z",
        "dateUpdated": "2026-09-16T15:50:48.246Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92361 (GCVE-0-2026-92361)

    Vulnerability from nvd – Published: 2026-09-16 13:00 – Updated: 2026-09-16 19:15
    VLAI
    Title
    ag-ui-protocol ag-ui SSE Client client.go resource consumption
    Summary
    A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption. The attack can be executed remotely. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 19:15 UTC
    CWE
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 1.0
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92361",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T19:15:03.168748Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T19:15:11.805Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "SSE Client"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption. The attack can be executed remotely. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-404",
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:00:10.023Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-405447 | ag-ui-protocol ag-ui SSE Client client.go resource consumption",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/405447"
            },
            {
              "name": "VDB-405447 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/405447/cti"
            },
            {
              "name": "CVE-2026-92361 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92361"
            },
            {
              "name": "Submit #934952 | ag-ui-protocol ag-ui v1.0 CWE-400",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934952"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2438"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2700"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-16T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-16T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-16T07:41:31.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui SSE Client client.go resource consumption",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92361",
        "datePublished": "2026-09-16T13:00:10.023Z",
        "dateReserved": "2026-09-16T05:36:08.433Z",
        "dateUpdated": "2026-09-16T19:15:11.805Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92360 (GCVE-0-2026-92360)

    Vulnerability from nvd – Published: 2026-09-16 12:30 – Updated: 2026-09-22 15:45
    VLAI
    Title
    ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validation
    Summary
    A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 15:10 UTC
    CWE
    • CWE-346 - Origin Validation Error
    • CWE-345 - Insufficient Verification of Data Authenticity
    References
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 1.0
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92360",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T15:10:01.076643Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T15:45:46.190Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Event Application Layer"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-346",
                  "description": "Origin Validation Error",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:30:09.510Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-405446 | ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validation",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/405446"
            },
            {
              "name": "VDB-405446 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/405446/cti"
            },
            {
              "name": "CVE-2026-92360 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92360"
            },
            {
              "name": "Submit #934950 | ag-ui-protocol ag-ui v1.0 CWE-346",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934950"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2437"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2701"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-16T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-16T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-16T07:41:53.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validation",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92360",
        "datePublished": "2026-09-16T12:30:09.510Z",
        "dateReserved": "2026-09-16T05:36:05.161Z",
        "dateUpdated": "2026-09-22T15:45:46.190Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92359 (GCVE-0-2026-92359)

    Vulnerability from nvd – Published: 2026-09-16 12:00 – Updated: 2026-09-16 13:15 X_Open Source
    VLAI
    Title
    ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy
    Summary
    A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipulation results in permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. Upgrading to version AGUI.Abstractions@0.0.6 is sufficient to fix this issue. The patch is identified as 9b143b9668fa52c2054ede9d34a45ac4b4401089. It is suggested to upgrade the affected component.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 13:15 UTC
    CWE
    • CWE-942 - Permissive Cross-domain Policy with Untrusted Domains
    • CWE-346 - Origin Validation Error
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 0.3.0
    Unaffected: AGUI.Abstractions@0.0.6
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92359",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T13:15:05.598960Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T13:15:16.227Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "CORSMiddleware"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.3.0"
                },
                {
                  "status": "unaffected",
                  "version": "AGUI.Abstractions@0.0.6"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "colorfullbz (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipulation results in permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. Upgrading to version AGUI.Abstractions@0.0.6 is sufficient to fix this issue. The patch is identified as 9b143b9668fa52c2054ede9d34a45ac4b4401089. It is suggested to upgrade the affected component."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 2.3,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 2.6,
                "vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-942",
                  "description": "Permissive Cross-domain Policy with Untrusted Domains",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-346",
                  "description": "Origin Validation Error",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:00:16.220Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-405445 | ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/405445"
            },
            {
              "name": "VDB-405445 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/405445/cti"
            },
            {
              "name": "CVE-2026-92359 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92359"
            },
            {
              "name": "Submit #934120 | ag-ui-protocol  ag-ui 0.3.0 CWE-942",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934120"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2433"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2492"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/commit/9b143b9668fa52c2054ede9d34a45ac4b4401089"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/releases/tag/AGUI.Abstractions%400.0.6"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-16T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-16T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-16T07:41:24.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92359",
        "datePublished": "2026-09-16T12:00:16.220Z",
        "dateReserved": "2026-09-16T05:36:01.573Z",
        "dateUpdated": "2026-09-16T13:15:16.227Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92184 (GCVE-0-2026-92184)

    Vulnerability from nvd – Published: 2026-09-15 23:30 – Updated: 2026-09-17 16:57 X_Open Source
    VLAI
    Title
    ag-ui-protocol ag-ui Multimodal Content utils.py urllib.request.urlopen server-side request forgery
    Summary
    A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The manipulation of the argument Value results in server-side request forgery. The attack can be executed remotely. The patch is identified as bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189. It is advisable to implement a patch to correct this issue.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 16:57 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 0.3.0
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92184",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T16:57:05.212304Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T16:57:15.679Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Multimodal Content"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.3.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "colorfullbz (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The manipulation of the argument Value results in server-side request forgery. The attack can be executed remotely. The patch is identified as bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189. It is advisable to implement a patch to correct this issue."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-15T23:30:12.366Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-404437 | ag-ui-protocol ag-ui Multimodal Content utils.py urllib.request.urlopen server-side request forgery",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/404437"
            },
            {
              "name": "VDB-404437 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/404437/cti"
            },
            {
              "name": "CVE-2026-92184 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92184"
            },
            {
              "name": "Submit #934100 | ag-ui-protocol ag-ui 0.3.0 CWE-918",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934100"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2432"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2491"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/commit/bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-15T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-15T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-15T20:13:42.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui Multimodal Content utils.py urllib.request.urlopen server-side request forgery",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92184",
        "datePublished": "2026-09-15T23:30:12.366Z",
        "dateReserved": "2026-09-15T18:08:36.657Z",
        "dateUpdated": "2026-09-17T16:57:15.679Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101101 (GCVE-0-2026-101101)

    Vulnerability from cvelistv5 – Published: 2026-09-28 17:45 – Updated: 2026-09-28 18:13 X_Open Source
    VLAI
    Title
    ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception
    Summary
    A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitation of the attack is possible. Upgrading to version 2026-09-08 is capable of addressing this issue. The identifier of the patch is 30f8c794d5b73df5c610153043db502b2cc106cc. Upgrading the affected component is recommended.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 18:13 UTC
    CWE
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 2026-09-07
    Unaffected: 2026-09-08
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101101",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T18:13:26.343570Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T18:13:33.954Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Middleware"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "2026-09-07"
                },
                {
                  "status": "unaffected",
                  "version": "2026-09-08"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitation of the attack is possible. Upgrading to version 2026-09-08 is capable of addressing this issue. The identifier of the patch is 30f8c794d5b73df5c610153043db502b2cc106cc. Upgrading the affected component is recommended."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-248",
                  "description": "Uncaught Exception",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T17:45:11.629Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-410976 | ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/410976"
            },
            {
              "name": "VDB-410976 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/410976/cti"
            },
            {
              "name": "CVE-2026-101101 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-101101"
            },
            {
              "name": "Submit #934981 | ag-ui-protocol ag-ui v1.0 CWE-248",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934981"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2444"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2493"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/commit/30f8c794d5b73df5c610153043db502b2cc106cc"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/releases/tag/release/2026-09-08"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-08T00:00:00.000Z",
              "value": "Countermeasure disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-28T04:59:01.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-101101",
        "datePublished": "2026-09-28T17:45:11.629Z",
        "dateReserved": "2026-09-28T02:53:41.099Z",
        "dateUpdated": "2026-09-28T18:13:33.954Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101100 (GCVE-0-2026-101100)

    Vulnerability from cvelistv5 – Published: 2026-09-28 17:30 – Updated: 2026-09-28 17:47 X_Open Source
    VLAI
    Title
    ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup
    Summary
    A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddleware of the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts of the component Middleware. Executing a manipulation can lead to incomplete cleanup. The attack may be launched remotely. Upgrading to version 2026-09-08 is able to resolve this issue. This patch is called c346119fe870b70f5c19738ee5119f3e1456e59d. It is suggested to upgrade the affected component.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 17:47 UTC
    CWE
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 2026-09-07
    Unaffected: 2026-09-08
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101100",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T17:47:46.613540Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T17:47:55.078Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Middleware"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "2026-09-07"
                },
                {
                  "status": "unaffected",
                  "version": "2026-09-08"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddleware of the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts of the component Middleware. Executing a manipulation can lead to incomplete cleanup. The attack may be launched remotely. Upgrading to version 2026-09-08 is able to resolve this issue. This patch is called c346119fe870b70f5c19738ee5119f3e1456e59d. It is suggested to upgrade the affected component."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5.5,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-459",
                  "description": "Incomplete Cleanup",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T17:30:15.988Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-410975 | ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/410975"
            },
            {
              "name": "VDB-410975 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/410975/cti"
            },
            {
              "name": "CVE-2026-101100 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-101100"
            },
            {
              "name": "Submit #934980 | ag-ui-protocol ag-ui v1.0 CWE-459",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934980"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2443"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2494"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/commit/c346119fe870b70f5c19738ee5119f3e1456e59d"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/releases/tag/release/2026-09-08"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-08T00:00:00.000Z",
              "value": "Countermeasure disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-28T04:58:57.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-101100",
        "datePublished": "2026-09-28T17:30:15.988Z",
        "dateReserved": "2026-09-28T02:53:37.761Z",
        "dateUpdated": "2026-09-28T17:47:55.078Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101099 (GCVE-0-2026-101099)

    Vulnerability from cvelistv5 – Published: 2026-09-28 17:15 – Updated: 2026-10-01 14:37
    VLAI
    Title
    ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition
    Summary
    A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. Performing a manipulation results in handling of exceptional conditions. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 14:37 UTC
    CWE
    • CWE-755 - Handling of Exceptional Conditions
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 2026-09-23
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101099",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T14:37:44.354460Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T14:37:54.433Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Kotlin Community SDK"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "2026-09-23"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. Performing a manipulation results in handling of exceptional conditions. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:ND/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-755",
                  "description": "Handling of Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T17:15:15.683Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-410974 | ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/410974"
            },
            {
              "name": "VDB-410974 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/410974/cti"
            },
            {
              "name": "CVE-2026-101099 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-101099"
            },
            {
              "name": "Submit #934974 | ag-ui-protocol ag-ui v1.0 CWE-755",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934974"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2442"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2657"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-28T04:58:51.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-101099",
        "datePublished": "2026-09-28T17:15:15.683Z",
        "dateReserved": "2026-09-28T02:53:34.487Z",
        "dateUpdated": "2026-10-01T14:37:54.433Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-101098 (GCVE-0-2026-101098)

    Vulnerability from cvelistv5 – Published: 2026-09-28 17:00 – Updated: 2026-09-28 17:48
    VLAI
    Title
    ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption
    Summary
    A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-28 17:48 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 2026-09-23
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-101098",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-28T17:48:04.263858Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-28T17:48:21.413Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "HTTP Handler"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "2026-09-23"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:ND/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-404",
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-28T17:00:16.182Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-410973 | ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/410973"
            },
            {
              "name": "VDB-410973 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/410973/cti"
            },
            {
              "name": "CVE-2026-101098 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-101098"
            },
            {
              "name": "Submit #934960 | ag-ui-protocol ag-ui v1.0 CWE-400",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934960"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2441"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2671"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-28T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-28T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-28T04:58:47.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-101098",
        "datePublished": "2026-09-28T17:00:16.182Z",
        "dateReserved": "2026-09-28T02:53:30.772Z",
        "dateUpdated": "2026-09-28T17:48:21.413Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92363 (GCVE-0-2026-92363)

    Vulnerability from cvelistv5 – Published: 2026-09-16 13:30 – Updated: 2026-09-18 17:49 X_Open Source
    VLAI
    Title
    ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption
    Summary
    A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. This patch is called ab6e0bc298996caac2b4b0b3ec0bd8d32a15a186. Applying a patch is advised to resolve this issue.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-18 17:49 UTC
    CWE
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 1.0
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92363",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-18T17:49:29.298534Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-18T17:49:43.680Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "JSON Parser"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. This patch is called ab6e0bc298996caac2b4b0b3ec0bd8d32a15a186. Applying a patch is advised to resolve this issue."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-404",
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:30:10.476Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-405449 | ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/405449"
            },
            {
              "name": "VDB-405449 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/405449/cti"
            },
            {
              "name": "CVE-2026-92363 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92363"
            },
            {
              "name": "Submit #934957 | ag-ui-protocol ag-ui v1.0 CWE-400",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934957"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2440"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2501"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/commit/ab6e0bc298996caac2b4b0b3ec0bd8d32a15a186"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-16T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-16T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-16T07:41:38.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92363",
        "datePublished": "2026-09-16T13:30:10.476Z",
        "dateReserved": "2026-09-16T05:36:15.071Z",
        "dateUpdated": "2026-09-18T17:49:43.680Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92362 (GCVE-0-2026-92362)

    Vulnerability from cvelistv5 – Published: 2026-09-16 13:15 – Updated: 2026-09-16 15:50
    VLAI
    Title
    ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption
    Summary
    A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a manipulation results in resource consumption. The attack is possible to be carried out remotely. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 15:50 UTC
    CWE
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 1.0
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92362",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T15:50:38.770449Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T15:50:48.246Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "SSE Frame Parser"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a manipulation results in resource consumption. The attack is possible to be carried out remotely. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-404",
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:15:10.426Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-405448 | ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/405448"
            },
            {
              "name": "VDB-405448 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/405448/cti"
            },
            {
              "name": "CVE-2026-92362 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92362"
            },
            {
              "name": "Submit #934956 | ag-ui-protocol ag-ui v1.0 CWE-400",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934956"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2439"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2500"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-16T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-16T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-16T07:41:35.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92362",
        "datePublished": "2026-09-16T13:15:10.426Z",
        "dateReserved": "2026-09-16T05:36:11.812Z",
        "dateUpdated": "2026-09-16T15:50:48.246Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92361 (GCVE-0-2026-92361)

    Vulnerability from cvelistv5 – Published: 2026-09-16 13:00 – Updated: 2026-09-16 19:15
    VLAI
    Title
    ag-ui-protocol ag-ui SSE Client client.go resource consumption
    Summary
    A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption. The attack can be executed remotely. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 19:15 UTC
    CWE
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 1.0
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92361",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T19:15:03.168748Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T19:15:11.805Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "SSE Client"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption. The attack can be executed remotely. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4,
                "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-400",
                  "description": "Resource Consumption",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-404",
                  "description": "Denial of Service",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T13:00:10.023Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-405447 | ag-ui-protocol ag-ui SSE Client client.go resource consumption",
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/vuln/405447"
            },
            {
              "name": "VDB-405447 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/405447/cti"
            },
            {
              "name": "CVE-2026-92361 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92361"
            },
            {
              "name": "Submit #934952 | ag-ui-protocol ag-ui v1.0 CWE-400",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934952"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2438"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2700"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-16T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-16T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-16T07:41:31.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui SSE Client client.go resource consumption",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92361",
        "datePublished": "2026-09-16T13:00:10.023Z",
        "dateReserved": "2026-09-16T05:36:08.433Z",
        "dateUpdated": "2026-09-16T19:15:11.805Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92360 (GCVE-0-2026-92360)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:30 – Updated: 2026-09-22 15:45
    VLAI
    Title
    ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validation
    Summary
    A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-22 15:10 UTC
    CWE
    • CWE-346 - Origin Validation Error
    • CWE-345 - Insufficient Verification of Data Authenticity
    References
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 1.0
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92360",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-22T15:10:01.076643Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-22T15:45:46.190Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Event Application Layer"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "meraklbz (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-346",
                  "description": "Origin Validation Error",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:30:09.510Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-405446 | ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validation",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/405446"
            },
            {
              "name": "VDB-405446 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/405446/cti"
            },
            {
              "name": "CVE-2026-92360 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92360"
            },
            {
              "name": "Submit #934950 | ag-ui-protocol ag-ui v1.0 CWE-346",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934950"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2437"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2701"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-16T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-16T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-16T07:41:53.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validation",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92360",
        "datePublished": "2026-09-16T12:30:09.510Z",
        "dateReserved": "2026-09-16T05:36:05.161Z",
        "dateUpdated": "2026-09-22T15:45:46.190Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92359 (GCVE-0-2026-92359)

    Vulnerability from cvelistv5 – Published: 2026-09-16 12:00 – Updated: 2026-09-16 13:15 X_Open Source
    VLAI
    Title
    ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy
    Summary
    A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipulation results in permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. Upgrading to version AGUI.Abstractions@0.0.6 is sufficient to fix this issue. The patch is identified as 9b143b9668fa52c2054ede9d34a45ac4b4401089. It is suggested to upgrade the affected component.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-16 13:15 UTC
    CWE
    • CWE-942 - Permissive Cross-domain Policy with Untrusted Domains
    • CWE-346 - Origin Validation Error
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 0.3.0
    Unaffected: AGUI.Abstractions@0.0.6
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92359",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-16T13:15:05.598960Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-16T13:15:16.227Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "CORSMiddleware"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.3.0"
                },
                {
                  "status": "unaffected",
                  "version": "AGUI.Abstractions@0.0.6"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "colorfullbz (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipulation results in permissive cross-domain policy with untrusted domains. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is described as difficult. Upgrading to version AGUI.Abstractions@0.0.6 is sufficient to fix this issue. The patch is identified as 9b143b9668fa52c2054ede9d34a45ac4b4401089. It is suggested to upgrade the affected component."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 2.3,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 3.1,
                "baseSeverity": "LOW",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 2.6,
                "vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-942",
                  "description": "Permissive Cross-domain Policy with Untrusted Domains",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-346",
                  "description": "Origin Validation Error",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-16T12:00:16.220Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-405445 | ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/405445"
            },
            {
              "name": "VDB-405445 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/405445/cti"
            },
            {
              "name": "CVE-2026-92359 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92359"
            },
            {
              "name": "Submit #934120 | ag-ui-protocol  ag-ui 0.3.0 CWE-942",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934120"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2433"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2492"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/commit/9b143b9668fa52c2054ede9d34a45ac4b4401089"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/releases/tag/AGUI.Abstractions%400.0.6"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-16T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-16T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-16T07:41:24.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92359",
        "datePublished": "2026-09-16T12:00:16.220Z",
        "dateReserved": "2026-09-16T05:36:01.573Z",
        "dateUpdated": "2026-09-16T13:15:16.227Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-92184 (GCVE-0-2026-92184)

    Vulnerability from cvelistv5 – Published: 2026-09-15 23:30 – Updated: 2026-09-17 16:57 X_Open Source
    VLAI
    Title
    ag-ui-protocol ag-ui Multimodal Content utils.py urllib.request.urlopen server-side request forgery
    Summary
    A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The manipulation of the argument Value results in server-side request forgery. The attack can be executed remotely. The patch is identified as bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189. It is advisable to implement a patch to correct this issue.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-17 16:57 UTC
    CWE
    • CWE-918 - Server-Side Request Forgery
    Impacted products
    Vendor Product Version
    ag-ui-protocol ag-ui Affected: 0.3.0
        cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-92184",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-17T16:57:05.212304Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-17T16:57:15.679Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Multimodal Content"
              ],
              "product": "ag-ui",
              "vendor": "ag-ui-protocol",
              "versions": [
                {
                  "status": "affected",
                  "version": "0.3.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "colorfullbz (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The manipulation of the argument Value results in server-side request forgery. The attack can be executed remotely. The patch is identified as bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189. It is advisable to implement a patch to correct this issue."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "Server-Side Request Forgery",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-15T23:30:12.366Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-404437 | ag-ui-protocol ag-ui Multimodal Content utils.py urllib.request.urlopen server-side request forgery",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/404437"
            },
            {
              "name": "VDB-404437 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/404437/cti"
            },
            {
              "name": "CVE-2026-92184 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-92184"
            },
            {
              "name": "Submit #934100 | ag-ui-protocol ag-ui 0.3.0 CWE-918",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/934100"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/issues/2432"
            },
            {
              "tags": [
                "issue-tracking",
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/pull/2491"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/commit/bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://github.com/ag-ui-protocol/ag-ui/"
            }
          ],
          "tags": [
            "x_open-source"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-15T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-15T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-15T20:13:42.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ag-ui-protocol ag-ui Multimodal Content utils.py urllib.request.urlopen server-side request forgery",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-92184",
        "datePublished": "2026-09-15T23:30:12.366Z",
        "dateReserved": "2026-09-15T18:08:36.657Z",
        "dateUpdated": "2026-09-17T16:57:15.679Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }