CVE-2026-105792

Source
https://cve.org/CVERecord?id=CVE-2026-105792
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105792.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105792
Aliases
  • GHSA-3hwr-qx8m-9xxx
Published
2026-10-06T14:10:52Z
Modified
2026-10-08T02:50:31Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Microsoft UFO: Authenticated task-result request can deadlock UFO server session manager
Details

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the /api/task_result/{task_name} endpoint calls SessionManager.get_result_by_task() in ufo/server/services/session_manager.py, which acquires a non-reentrant lock and then calls SessionManager.get_result() to acquire the same lock again when the task name maps to a session. An authenticated caller who knows or creates a mapped task name can therefore block the request indefinitely, and in the default single-process server configuration the blocked event-loop thread prevents other HTTP, WebSocket, and dependent background interactions. Unknown task names do not reach the nested call and are not affected. This issue is fixed in version 3.0.9.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-833"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105792.json"
}
References

Affected packages

Git / github.com/microsoft/ufo

Affected ranges

Type
GIT
Repo
https://github.com/microsoft/ufo
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.0.9"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.0.6
3.0.7
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105792.json"