CVE-2026-105792
Microsoft UFO: Authenticated task-result request can deadlock UFO server session manager
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the /api/task_result/{task_name} endpoint calls SessionManager.get_result_by_task() in ufo/server/services/session_manager.py, which acquires a non-reentrant lock and then calls SessionManager.get_result() to acquire the same lock again when the task name maps to a session. An authenticated caller who knows or creates a mapped task name can therefore block the request indefinitely, and in the default single-process server configuration the blocked event-loop thread prevents other HTTP, WebSocket, and dependent background interactions. Unknown task names do not reach the nested call and are not affected. This issue is fixed in version 3.0.9.
| CWE | CWE-833 |
| Vendor | microsoft |
| Product | ufo |
| Ecosystems | |
| Industries | TechnologyEnterprise |
| Published | Oct 6, 2026 |
Get instant alerts for microsoft ufo
Be the first to know when new medium vulnerabilities affecting microsoft ufo are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H