Description
A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a manipulation results in resource consumption. The attack is possible to be carried out remotely. The pull request to fix this issue awaits acceptance.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from manipulation of the SSE Frame Parser in ag-ui-client, causing uncontrolled resource consumption via the file sse.rs. An attacker can send crafted SSE frames which force the parser to perform excessive processing, leading to high CPU or memory use. This represents a classic instance of uncontrolled resource consumption (CWE‑400).

Affected Systems

The issue affects the ag-ui protocol product released as ag-ui version 1.0. The affected component is the server‑side SSE Frame Parser, which is invoked when a client initiates a Server‑Sent Events stream. No other product versions or operating systems were mentioned, so only the stated 1.0 release is confirmed.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity, and the EPSS score of less than 1% suggests a low probability of active exploitation. The flaw is remotely exploitable over the network by providing malformed SSE input. It is not listed in the CISA KEV catalog. Given its moderate severity and low but non‑zero risk, applying a patch or removing the vulnerable code is recommended as the highest priority action.

Generated by OpenCVE AI on September 18, 2026 at 05:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest release of ag-ui that incorporates the fix, or manually merge the pending pull request once it is accepted.
  • If a patch is not yet available, restrict the rate of inbound Server‑Sent Events connections or enforce strict input validation on SSE payloads to limit resource usage.
  • Deploy monitoring on CPU and memory metrics for the SSE Frame Parser process and alert on abnormal spikes that may indicate exploitation attempts.

Generated by OpenCVE AI on September 18, 2026 at 05:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a manipulation results in resource consumption. The attack is possible to be carried out remotely. The pull request to fix this issue awaits acceptance.
Title ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption
First Time appeared Ag-ui-protocol
Ag-ui-protocol ag-ui
Weaknesses CWE-400
CWE-404
CPEs cpe:2.3:a:ag-ui-protocol:ag-ui:*:*:*:*:*:*:*:*
Vendors & Products Ag-ui-protocol
Ag-ui-protocol ag-ui
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Ag-ui-protocol Ag-ui
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T15:50:48.246Z

Reserved: 2026-09-16T05:36:11.812Z

Link: CVE-2026-92362

cve-icon Vulnrichment

Updated: 2026-09-16T15:50:43.226Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T14:17:16.387

Modified: 2026-09-16T17:53:40.500

Link: CVE-2026-92362

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:15:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-404

    Improper Resource Shutdown or Release