CVE-2026-101098Medium· 4.3▾ SunlitA security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resou…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92362High· 7.3A vulnerability was detected in ag-ui-protocol ag-ui 1.0
CVE-2026-92363Medium· 4.3A flaw has been found in ag-ui-protocol ag-ui 1.0
CVE-2026-92361Medium· 4.3A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0
CVE-2026-101099Medium· 4.3A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23
CVE-2026-101100Medium· 5.4A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07
CVE-2026-101101Medium· 4.3A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07