CVE-2026-101098: ag-ui-protocol ag-ui HTTP JdkAgentHttpHandler.java readAllBytes resource consumption
A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the severity vector indicates that the attacker needs low-level privileges. No user interaction is required.
Which releases should be considered affected?
The issue affects ag-ui-protocol ag-ui through 2026-09-23. The provided information does not identify a fixed release.
Is a fix currently available?
A pull request intended to fix the issue is awaiting acceptance. The data does not indicate that an accepted patch or released update is available.