Resource Consumption Vulnerability in ag-ui Protocol by ag-ui
CVE-2026-101098

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101098?

A security vulnerability has been identified in ag-ui Protocol's HTTP Handler component, specifically within the readAllBytes function of JdkAgentHttpHandler.java. This flaw allows remote attackers to exploit the system, possibly leading to excessive resource consumption. The vulnerability presents operational risks as it can potentially overload systems handling multiple requests. A pull request to address this issue is currently pending acceptance.

Affected Version(s)

ag-ui 2026-09-23

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

meraklbz (VulDB User)
VulDB CNA Team
.