CVE-2026-105792: Microsoft UFO: Authenticated task-result request can deadlock UFO server session manager

Published Oct 6, 2026
·
Updated

Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the /api/taskresult/{taskname} endpoint calls SessionManager.getresultbytask() in ufo/server/services/sessionmanager.py, which acquires a non-reentrant lock and then calls SessionManager.getresult() to acquire the same lock again when the task name maps to a session. An authenticated caller who knows or creates a mapped task name can therefore block the request indefinitely, and in the default single-process server configuration the blocked event-loop thread prevents other HTTP, WebSocket, and dependent background interactions. Unknown task names do not reach the nested call and are not affected. This issue is fixed in version 3.0.9.

Affected Software

1 affected component
Microsoft UFO<3.0.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Microsoft UFO to a version that resolves this vulnerability.

    Fixed in 3.0.9

Event History

Oct 6, 2026
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can trigger the denial of service?

An authenticated caller can trigger it if they know or create a task name that maps to a session. Requests using unknown task names do not enter the nested lock path and are not affected.

2

How broadly does a blocked request affect the service?

In the default single-process server configuration, the blocked event-loop thread prevents other HTTP, WebSocket, and dependent background interactions. This can make the service unavailable beyond the individual task-result request.

3

What versions are affected and what fixes the issue?

Versions prior to 3.0.9 are affected. Upgrade to version 3.0.9, which fixes the nested non-reentrant lock acquisition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203