CVE-2026-92361: AG-UI-Protocol AG-UI
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption. The attack can be executed remotely. The pull request to fix this issue awaits acceptance.
Affected products
- AG-UI-Protocol AG-UI: version 1.0 only
Published 2026-09-16. Last modified 2026-09-28.