Description
A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion / Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability exists in the updateComponents function of the basic_functions.ts file within the Update Components component. It allows an attacker to manipulate input in a manner that causes excessive CPU or memory consumption, potentially looping or holding resources indefinitely. The weakness aligns with CWE-400 (Resource Exhaustion) and CWE-404 (Improper Resource Shutdown or Release), which can lead to degraded performance or outright crashes when the application stalls or becomes unresponsive.

Affected Systems

Versions 0.9 and 0.9.1 of the a2ui project are vulnerable. The project’s repository indicates no official patch has been released yet, leaving all deployed instances of these versions at risk. The problematic endpoint can be triggered remotely, and no authentication requirements are documented.

Risk and Exploitability

The CVSS score of 5.3 signals a moderate severity, while the EPSS score of less than 1% suggests a low probability of immediate exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the attack vector is remote, any exposed installation is potentially vulnerable, and an exploit could consume system resources to the point of denial of service or crash. Although no active exploit is known, the possibility of disruption should be considered when planning defenses.

Generated by OpenCVE AI on September 17, 2026 at 22:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade a2ui to a version that addresses the updateComponents resource consumption issue, if one is available.
  • Restrict or disable external access to the Update Components endpoint so that only trusted entities can invoke it.
  • Implement monitoring of CPU and memory usage for the application and enforce rate limiting or connection throttling to mitigate prolonged resource abuse.

Generated by OpenCVE AI on September 17, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Title a2ui-project a2ui Update Components basic_functions.ts updateComponents resource consumption
First Time appeared A2ui-project
A2ui-project a2ui
Weaknesses CWE-400
CWE-404
CPEs cpe:2.3:a:a2ui-project:a2ui:*:*:*:*:*:*:*:*
Vendors & Products A2ui-project
A2ui-project a2ui
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

A2ui-project A2ui
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T17:51:42.059Z

Reserved: 2026-09-16T05:19:40.243Z

Link: CVE-2026-92356

cve-icon Vulnrichment

Updated: 2026-09-16T17:51:32.903Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T11:17:25.553

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-92356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:00:13Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-404

    Improper Resource Shutdown or Release