CVE-2026-92356

Source
https://cve.org/CVERecord?id=CVE-2026-92356
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92356.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92356
Published
2026-09-16T10:15:10Z
Modified
2026-09-18T03:48:40Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
a2ui-project a2ui Update Components basic_functions.ts updateComponents resource consumption
Details

A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-400",
        "CWE-404"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92356.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "0.9.1"
                },
                {
                    "last_affected": "0.9.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/a2ui-project/a2ui

Affected ranges

Type
GIT
Repo
https://github.com/a2ui-project/a2ui
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.9"
        },
        {
            "last_affected": "0.9"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.9
v0.*
v0.8
v0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92356.json"