Description
A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption. The attack can be executed remotely. The pull request to fix this issue awaits acceptance.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote resource exhaustion (Denial of Service)
Action: Await Patch
AI Analysis

Impact

This vulnerability originates in the SSE Client of ag-ui version 1.0, where manipulation of an unknown function in client.go can drain system resources. The effect is a denial of service caused by uncontrolled resource consumption, as identified by CWE-400, and involves improper error handling or path resolution identified by CWE-404. The description indicates that the attack vector is remote, implying that a network attacker can trigger the exploit without local access.

Affected Systems

Vendor ag-ui-protocol offers the affected product ag-ui, version 1.0. No other versions are listed in the CVE record.

Risk and Exploitability

The CVSS score of 5.3 suggests moderate severity, and an EPSS score of less than 1% indicates a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The remote nature of the attack and the lack of a public patch mean that immediate exploitation poses limited risk, but the potential for resource exhaustion remains if the vulnerability remains unpatched.

Generated by OpenCVE AI on September 18, 2026 at 05:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor patch or upgrade to a later version of ag-ui once the fix is released on the official repository or package channels.
  • Until a patch is available, limit exposure by restricting network access to the SSE Client interface, monitoring for abnormal resource consumption, and setting limits on connection or message size.
  • Implement generic resource‑limit controls such as cgroups or systemd slices, or configure the application runtime to enforce quotas on CPU and memory usage for the SSE Client process.

Generated by OpenCVE AI on September 18, 2026 at 05:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption. The attack can be executed remotely. The pull request to fix this issue awaits acceptance.
Title ag-ui-protocol ag-ui SSE Client client.go resource consumption
First Time appeared Ag-ui-protocol
Ag-ui-protocol ag-ui
Weaknesses CWE-400
CWE-404
CPEs cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
Vendors & Products Ag-ui-protocol
Ag-ui-protocol ag-ui
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Ag-ui-protocol Ag-ui
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T19:15:11.805Z

Reserved: 2026-09-16T05:36:08.433Z

Link: CVE-2026-92361

cve-icon Vulnrichment

Updated: 2026-09-16T19:15:08.778Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T13:18:09.290

Modified: 2026-09-28T21:10:00.140

Link: CVE-2026-92361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:30:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-404

    Improper Resource Shutdown or Release