CVE-2026-92363: AG-UI-Protocol AG-UI

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed from remote. This patch is called ab6e0bc298996caac2b4b0b3ec0bd8d32a15a186. Applying a patch is advised to resolve this issue.

Affected products

Published 2026-09-16. Last modified 2026-09-18.