CVE-2026-92356: a2ui-project a2ui Update Components basic_functions.ts updateComponents resource consumption
A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basicfunctions.ts of the component Update Components. Executing a manipulation can lead to resource consumption. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the CVSS vector indicates that the attacker needs low-level privileges. No user interaction is required.
What is the expected impact?
Successful exploitation can cause resource consumption and affect availability. The provided metrics indicate no confidentiality or integrity impact.
Which versions are identified as affected?
The issue is reported in a2ui-project a2ui versions 0.9 and 0.9.1, affecting the Update Components component's basic_functions.ts updateComponents function.
Is a fix available?
The provided information does not identify a patch or fixed version. It states that the project was notified through an issue report but had not responded at the time of the report.