Impact
A flaw exists in the JSON Parser within ag‑ui 1.0, specifically in src/stream/sse_parser.cpp. Manipulating JSON input can trigger uncontrolled resource consumption, leading to performance degradation or denial of service. The attack may be performed from remote. The issue arises from unchecked resource usage (CWE‑400) and improper handling of input boundaries (CWE‑404). Crafting oversized or malformed JSON can cause the parser to allocate excessive memory or enter long processing loops, potentially exhausting CPU, memory, or I/O on the hosting machine and disrupting the availability of the application or other services that rely on ag‑ui.
Affected Systems
The affected component is ag‑ui‑protocol’s ag‑ui library, version 1.0. The vulnerability resides in the JSON parsing module within src/stream/sse_parser.cpp. No other versions are mentioned as affected in the available information.
Risk and Exploitability
The CVSS score of 5.3 classifies this problem as moderate severity. With an EPSS score of less than 1 % and no mention in the CISA KEV catalog, the likelihood of exploitation today is low, but the remote nature of the attack and the potential for resource exhaustion mean that it remains a viable threat, especially for high‑traffic or exposed deployments. An attacker who can reach the SSE endpoint could repeatedly send crafted JSON streams to consume CPU or memory, leading to a denial of service that can be mitigated by rate limiting, size restrictions, or patching.
OpenCVE Enrichment