CVE-2026-101099
Received Received - Intake

Heap Overflow in ag-ui-protocol ag-ui via Kotlin Community SDK

Vulnerability report for CVE-2026-101099, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. Performing a manipulation results in handling of exceptional conditions. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
ag-ui ag-ui to 2026-09-23 (inc)
kotlin_community_sdk kotlin_community_sdk *
ag-ui-protocol ag-ui to 2026-09-23 (inc)
kotlin community_sdk to 2026-09-23 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-755 The product does not handle or incorrectly handles an exceptional condition.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in the ag-ui-protocol and Kotlin Community SDK. It occurs when handling exceptional conditions in the SseParser.kt file, potentially allowing remote attackers to cause a StackOverflowError during JSON parsing. The lack of depth limits or proper error handling can lead to process termination or uncontrolled memory consumption.

Detection Guidance

Monitor for abnormal memory usage or process termination during JSON parsing with kotlinx.serialization. Check for StackOverflowError exceptions in logs. Inspect network traffic for unusually large payloads or repeated requests to ag-ui endpoints.

Impact Analysis

This vulnerability can impact you by causing your application to crash or consume excessive memory, leading to degraded performance or complete unavailability. Attackers could exploit it by sending malicious data to endpoints using the affected SDKs, triggering crashes or resource exhaustion.

Compliance Impact

The vulnerability primarily impacts system availability due to uncontrolled resource consumption or process termination, which could disrupt services handling sensitive data. GDPR requires ensuring availability of processing systems, while HIPAA mandates safeguards against unauthorized data access or disruption. This issue may lead to service outages, potentially violating these requirements if not mitigated.

Mitigation Strategies

Apply the patch from pull request #2657 to enforce payload size limits (1 MiB for SSE lines, 8 MiB for event data) and add error handling for StackOverflowError. Update the Kotlin Community SDK to the fixed version. Monitor system resources for signs of uncontrolled memory growth.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101099. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart