CVE-2026-101099
A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the componen
CVSS
4.3
Medium
EPSS
0.5%
p41
KEV
—
Exploit Today
12
0-100
Published: Sep 28, 2026 · Last modified: Oct 1, 2026 · CWE-755
0.5%EPSS · 30 days0.5%
2026-09-292026-10-04
A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. Performing a manipulation results in handling of exceptional conditions. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
- github.comhttps://github.com/ag-ui-protocol/ag-ui/
- github.comhttps://github.com/ag-ui-protocol/ag-ui/issues/2442
- github.comhttps://github.com/ag-ui-protocol/ag-ui/pull/2657
- vuldb.comhttps://vuldb.com/cve/CVE-2026-101099
- vuldb.comhttps://vuldb.com/submit/934974
- vuldb.comhttps://vuldb.com/vuln/410974
- vuldb.comhttps://vuldb.com/vuln/410974/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-96277—34.6%
——10Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.3dCVE-2026-96294—34.6%
——10Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.3dCVE-2026-90440—34.6%
——10Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.3dCVE-2026-94651—34.6%
——10improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.3dCVE-2026-94639—34.6%
——10improper handling of exceptional conditions, Allocation of resources without limits or throttling, Uncaught exception vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.3dCVE-2026-1022745.9 MED26.6%
——8PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a JWK Set contains a malformed RSA key alongside otherwise usable keys. As a result, one malformed member aborts construction of the entire PyJWKSet. Consequently, applications can experience authentication failures or request-level denial of service. This issue is fixed in version 2.14.0.6d