JSON Parser Flaw in ag-ui by ag-ui-protocol Leads to Resource Consumption
CVE-2026-92363

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92363?

A critical flaw has been identified in the ag-ui-protocol's JSON parser within the ag-ui product version 1.0. This vulnerability resides in a specific function within the file src/stream/sse_parser.cpp, where an attacker can exploit the flaw to execute manipulation tactics that result in excessive resource consumption. This issue has the potential to be exploited remotely, making it imperative for users to apply the recommended patch (commit ab6e0bc298996caac2b4b0b3ec0bd8d32a15a186) to mitigate the risks associated with this vulnerability. It is essential for those using the affected version to address this issue promptly to maintain system integrity.

Affected Version(s)

ag-ui 1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

meraklbz (VulDB User)
.