ag-ui-protocol has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 5.3 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (3) and CWE-404 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2026-92362High· 7.3A vulnerability was detected in ag-ui-protocol ag-ui 1.040CVE-2026-92360Medium· 6.3A weakness has been identified in ag-ui-protocol ag-ui 1.035CVE-2026-92184Medium· 6.3A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.035CVE-2026-92363Medium· 4.3A flaw has been found in ag-ui-protocol ag-ui 1.024CVE-2026-92361Medium· 4.3A security vulnerability has been detected in ag-ui-protocol ag-ui 1.024
ag-ui-protocol vulnerabilities
CVEs affecting ag-ui-protocol, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-92362High· 7.3A vulnerability was detected in ag-ui-protocol ag-ui 1.0
A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a manipulation results in resource consumption. The attac…
CVE-2026-92363Medium· 4.3A flaw has been found in ag-ui-protocol ag-ui 1.0
A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed…
CVE-2026-92361Medium· 4.3A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0
A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption.…
CVE-2026-92359Low· 3.1A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0
A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipu…
CVE-2026-92360Medium· 6.3A weakness has been identified in ag-ui-protocol ag-ui 1.0
A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_STA…
CVE-2026-92184Medium· 6.3A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0
A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The manipulati…