CVE-2026-101098
ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
| CWE | CWE-400 CWE-404 |
| Vendor | ag-ui-protocol |
| Product | ag-ui |
| Published | Sep 28, 2026 |
| Last Updated | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for ag-ui-protocol ag-ui
Be the first to know when new medium vulnerabilities affecting ag-ui-protocol ag-ui are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
ag-ui-protocol / ag-ui
2026-09-23
References
vuldb.com: https://vuldb.com/vuln/410973 vuldb.com: https://vuldb.com/vuln/410973/cti vuldb.com: https://vuldb.com/cve/CVE-2026-101098 vuldb.com: https://vuldb.com/submit/934960 github.com: https://github.com/ag-ui-protocol/ag-ui/issues/2441 github.com: https://github.com/ag-ui-protocol/ag-ui/pull/2671 github.com: https://github.com/ag-ui-protocol/ag-ui/
Credits
๐ meraklbz (VulDB User) VulDB CNA Team