CVE-2026-105792: Microsoft UFO: Authenticated task-result request can deadlock UFO server session manager
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the /api/taskresult/{taskname} endpoint calls SessionManager.getresultbytask() in ufo/server/services/sessionmanager.py, which acquires a non-reentrant lock and then calls SessionManager.getresult() to acquire the same lock again when the task name maps to a session. An authenticated caller who knows or creates a mapped task name can therefore block the request indefinitely, and in the default single-process server configuration the blocked event-loop thread prevents other HTTP, WebSocket, and dependent background interactions. Unknown task names do not reach the nested call and are not affected. This issue is fixed in version 3.0.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Microsoft UFOto a version that resolves this vulnerability.Fixed in 3.0.9
Event History
Frequently Asked Questions
Who can trigger the denial of service?
An authenticated caller can trigger it if they know or create a task name that maps to a session. Requests using unknown task names do not enter the nested lock path and are not affected.
How broadly does a blocked request affect the service?
In the default single-process server configuration, the blocked event-loop thread prevents other HTTP, WebSocket, and dependent background interactions. This can make the service unavailable beyond the individual task-result request.
What versions are affected and what fixes the issue?
Versions prior to 3.0.9 are affected. Upgrade to version 3.0.9, which fixes the nested non-reentrant lock acquisition.