CVE-2026-92114: a2ui-project a2ui Basic Catalog safe_regex.ts redos
Published Sep 15, 2026
·Updated
A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/webcore/src/v09/basiccatalog/functions/saferegex.ts of the component Basic Catalog. Such manipulation leads to inefficient regular expression complexity. The attack can be launched remotely.
Affected Software
1 affected component
a2ui-project/a2ui<=0.10.6
Event History
Sep 15, 2026
CVE Published
via MITRE·09:30 PM
Data Sourced
via MITRE·09:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which releases are known to be affected?
a2ui-project a2ui versions up to and including 0.10.6 are identified as affected.
2
Can this be exploited remotely without authentication or user interaction?
Yes. The supplied vector indicates network-based exploitation with low attack complexity, no required privileges, and no user interaction.
3
What is the expected impact of successful exploitation?
The reported impact is limited to availability. Manipulating the affected functionality can cause inefficient regular expression processing, potentially degrading service performance.