CVE-2026-101098

Source
https://cve.org/CVERecord?id=CVE-2026-101098
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101098.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-101098
Published
2026-09-28T17:00:16Z
Modified
2026-09-30T03:47:00Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption
Details

A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-400",
        "CWE-404"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101098.json"
}
References

Affected packages

Git / github.com/ag-ui-protocol/ag-ui

Affected ranges

Type
GIT
Repo
https://github.com/ag-ui-protocol/ag-ui
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2026-09-23"
        },
        {
            "last_affected": "2026-09-23"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

Other
2026-09-23
release/2026-09-23
ag_ui_strands@0.*
ag_ui_strands@0.4.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101098.json"