{"id":"CVE-2026-92361","title":"A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0","summary":"A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption.…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-400","CWE-404"],"vendor":"ag-ui-protocol","product":"ag-ui","affected":["ag-ui 1.0"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T20:17:47.813","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92361","references":[{"url":"https://github.com/ag-ui-protocol/ag-ui/","label":"cna@vuldb.com"},{"url":"https://github.com/ag-ui-protocol/ag-ui/issues/2438","label":"cna@vuldb.com"},{"url":"https://github.com/ag-ui-protocol/ag-ui/pull/2700","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-92361","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/934952","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/405447","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/405447/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-16T19:15:03.168748Z"},"ingestedAt":"2026-09-16T13:56:12.613Z","epss":0.0051,"epssPercentile":0.42357,"slug":"CVE-2026-92361","body":"## Overview\n\nA security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption. The attack can be executed remotely. The pull request to fix this issue awaits acceptance.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}