CVE-2026-92362: ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption
A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a manipulation results in resource consumption. The attack is possible to be carried out remotely. The pull request to fix this issue awaits acceptance.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems using ag-ui-protocol ag-ui 1.0 with the affected SSE Frame Parser code in crates/ag-ui-client/src/sse.rs are potentially exposed. The issue can be exploited remotely.
Does exploitation require authentication or user interaction?
No privileges or user interaction are required according to the supplied vector. The attack complexity is rated low.
What is the likely impact of exploitation?
Manipulation of the affected SSE frame parsing functionality can cause resource consumption. The reported CVSS impacts include low confidentiality, integrity, and availability impact.
Is a fix available?
A pull request to fix the issue exists but is awaiting acceptance. No accepted patch or fixed version is identified in the provided data.