在 ag-ui-protocol ag-ui 至 2026-09-23 的版本中检测到一个安全漏洞。该漏洞影响 HTTP Handler 组件中 JdkAgentHttpHandler.java 文件的 readAllBytes 函数。此类操作会导致资源消耗问题。该攻击可由远程发起。修复此问题的拉取请求(Pull Request)目前正在等待合并审批。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ag-ui-protocol | ag-ui | 2026-09-23 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ag-ui-protocol | ag-ui | 2026-09-23 |
cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101100 | 5.4 MEDIUM | ag-ui-protocol ag-ui Middleware filter-tool-calls.ts FilterToolCallsMiddleware cleanup |
| CVE-2026-101099 | 4.3 MEDIUM | ag-ui-protocol ag-ui Kotlin Community SDK SseParser.kt exceptional condition |
| CVE-2026-101101 | 4.3 MEDIUM | ag-ui-protocol ag-ui Middleware convert.ts JSON.parse uncaught exception |
No comments yet