๐Ÿ” CVE Alert

CVE-2026-101098

MEDIUM 4.3

ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.

CWE CWE-400 CWE-404
Vendor ag-ui-protocol
Product ag-ui
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for ag-ui-protocol ag-ui

Be the first to know when new medium vulnerabilities affecting ag-ui-protocol ag-ui are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ag-ui-protocol / ag-ui
2026-09-23

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/410973 vuldb.com: https://vuldb.com/vuln/410973/cti vuldb.com: https://vuldb.com/cve/CVE-2026-101098 vuldb.com: https://vuldb.com/submit/934960 github.com: https://github.com/ag-ui-protocol/ag-ui/issues/2441 github.com: https://github.com/ag-ui-protocol/ag-ui/pull/2671 github.com: https://github.com/ag-ui-protocol/ag-ui/

Credits

๐Ÿ” meraklbz (VulDB User) VulDB CNA Team