CVE-2026-101098
Received Received - Intake

Resource Consumption in ag-ui-protocol ag-ui via HTTP Handler

Vulnerability report for CVE-2026-101098, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function readAllBytes of the file JdkAgentHttpHandler.java of the component HTTP Handler. Such manipulation leads to resource consumption. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ag-ui ag-ui to 2026-09-23 (inc)
ag-ui-protocol ag-ui to 2026-09-23 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a resource consumption issue in the ag-ui-protocol library's HTTP handler. The function readAllBytes in JdkAgentHttpHandler.java reads the entire HTTP request body into memory without size limits, which can cause memory exhaustion if large requests are sent repeatedly. The attack can be launched remotely.

Detection Guidance

Monitor for unusually high memory usage on the server hosting ag-ui, particularly in the Java process. Check for repeated HTTP 413 errors if the fix is applied. Inspect network traffic for large POST requests to the agent endpoint. Use tools like netstat or ss to track connections and lsof to check open files and memory allocations.

Impact Analysis

An attacker could send large POST requests to the vulnerable endpoint, causing the server to consume excessive memory. This may lead to performance degradation, crashes, or denial-of-service conditions. The impact depends on deployment configurations and existing protections.

Compliance Impact

The vulnerability could lead to uncontrolled resource consumption via memory exhaustion from large POST requests, potentially causing denial-of-service conditions. This may impact compliance by disrupting availability requirements in GDPR (Article 32) and HIPAA (Security Rule Β§164.312(a)(1)), which mandate safeguards against service disruptions and unauthorized resource usage.

Mitigation Strategies

Apply the pull request fix to enforce a configurable maximum body size (default 8 MiB) in JdkAgentHttpHandler.java. Configure reverse-proxy body limits (e.g., Nginx client_max_body_size, Apache LimitRequestBody) to match or exceed the handler's limit. Monitor for HTTP 413 errors and adjust limits as needed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101098. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart