---
id: CVE-2026-101098
title: >-
  A security vulnerability has been detected in ag-ui-protocol ag-ui up to
  2026-09-23
summary: >-
  A security vulnerability has been detected in ag-ui-protocol ag-ui up to
  2026-09-23. Affected by this issue is the function readAllBytes of the file
  JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation
  leads to resou…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-400
  - CWE-404
vendor: ag-ui-protocol
product: ag-ui
affected:
  - ag-ui 2026-09-23
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T18:17:16.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101098'
references:
  - url: 'https://github.com/ag-ui-protocol/ag-ui/'
    label: cna@vuldb.com
  - url: 'https://github.com/ag-ui-protocol/ag-ui/issues/2441'
    label: cna@vuldb.com
  - url: 'https://github.com/ag-ui-protocol/ag-ui/pull/2671'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-101098'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/934960'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410973'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410973/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-28T17:48:04.263858Z'
ingestedAt: '2026-09-28T17:16:27.805Z'
---

## Overview

A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
