Denial of Service in Microsoft UFO Prior to Version 3.0.9
CVE-2026-105792
6.5MEDIUM
What is CVE-2026-105792?
The issue in Microsoft UFO arises from a flaw in the /api/task_result/{task_name} endpoint, which uses a non-reentrant lock when handling certain session-related operations. An authenticated user who possesses knowledge of or can create a specific task name can inadvertently (or purposefully) block the server's request processing indefinitely. This blockage impedes the default single-process server's event loop, effectively halting other critical interactions, including HTTP and WebSocket communications. It's crucial to note that task names that do not map to a session are unaffected by this issue. The problem has been remedied in version 3.0.9 of the product.
Affected Version(s)
UFO < 3.0.9