CVE-2026-101101
Received Received - Intake

JSON.parse Exception in ag-ui-protocol ag-ui Middleware

Vulnerability report for CVE-2026-101101, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitation of the attack is possible. Upgrading to version 2026-09-08 is capable of addressing this issue. The identifier of the patch is 30f8c794d5b73df5c610153043db502b2cc106cc. Upgrading the affected component is recommended.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ag-ui-protocol ag-ui to 2026-09-07 (inc)
ag-ui-protocol ag-ui 2026-09-08

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101101 is an uncaught JSON.parse error in the ag-ui-protocol/ag-ui library. It occurs when malformed JSON from a server reaches the JSON.parse function without proper error handling. This causes the stream to terminate immediately or lead to unhandled promise rejections, affecting availability.

Detection Guidance

To detect this vulnerability, check if your system is running ag-ui-protocol ag-ui versions up to 2026-09-07. Inspect the legacy/convert.ts file for unguarded JSON.parse calls and the a2a-middleware/src/index.ts for promises without .catch handlers. Look for stream terminations or unhandled rejections in logs.

Impact Analysis

This vulnerability can cause stream termination or hangs when invalid JSON is processed. It may lead to unhandled errors, stalled streams, or incorrect error handling, disrupting normal application flow and requiring manual intervention to recover.

Compliance Impact

This vulnerability primarily impacts system availability by causing stream termination or unhandled promise rejections due to malformed JSON parsing. It does not directly expose or leak sensitive data, which is a key concern for GDPR and HIPAA compliance. However, prolonged stream hangs or stalled processes could indirectly affect service availability, potentially violating uptime requirements in regulated environments.

Mitigation Strategies

Upgrade ag-ui-protocol ag-ui to version 2026-09-08 or later. Apply the patch identified by 30f8c794d5b73df5c610153043db502b2cc106cc. Ensure JSON.parse calls are wrapped in try/catch blocks and add .catch handlers to all parsing promises in the middleware.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101101. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart