Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92363— ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption

Quick assessment

Affected
ag-ui-protocol ag-ui
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 ag-ui-protocol ag-ui 1.0 中发现了一个缺陷。受影响的是组件 JSON Parser 中文件 src/stream/sse_parser.cpp 的一个未知函数。执行相应的操作可能导致资源消耗(资源耗尽)。该攻击可远程发起。此补丁编号为 ab6e0bc298996caac2b4b0b3ec0bd8d32a15a186。建议应用该补丁以解决此问题。

CVSS 4.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92363

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. This patch is called ab6e0bc298996caac2b4b0b3ec0bd8d32a15a186. Applying a patch is advised to resolve this issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ag-ui-protocol ag-ui 1.0 cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-92363

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92363

登录查看更多情报信息。

Patches & Fixes for CVE-2026-92363 (2)

Other References for CVE-2026-92363 (1)

Same Patch Batch · ag-ui-protocol · 2026-09-16 · 5 CVEs total

CVE-2026-92362 7.3 HIGH ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption
CVE-2026-92360 6.3 MEDIUM ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput origin validati
CVE-2026-92361 4.3 MEDIUM ag-ui-protocol ag-ui SSE Client client.go resource consumption
CVE-2026-92359 3.1 LOW ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain policy

IV. Related Vulnerabilities

V. Comments for CVE-2026-92363

No comments yet


Leave a comment