Impact
The vulnerability arises from manipulation of the SSE Frame Parser in ag-ui-client, causing uncontrolled resource consumption via the file sse.rs. An attacker can send crafted SSE frames which force the parser to perform excessive processing, leading to high CPU or memory use. This represents a classic instance of uncontrolled resource consumption (CWE‑400).
Affected Systems
The issue affects the ag-ui protocol product released as ag-ui version 1.0. The affected component is the server‑side SSE Frame Parser, which is invoked when a client initiates a Server‑Sent Events stream. No other product versions or operating systems were mentioned, so only the stated 1.0 release is confirmed.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity, and the EPSS score of less than 1% suggests a low probability of active exploitation. The flaw is remotely exploitable over the network by providing malformed SSE input. It is not listed in the CISA KEV catalog. Given its moderate severity and low but non‑zero risk, applying a patch or removing the vulnerable code is recommended as the highest priority action.
OpenCVE Enrichment