CVE-2026-92356 PUBLISHED

a2ui-project a2ui Update Components basic_functions.ts updateComponents resource consumption

Assigner: VulDB
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 5.3

Product Status

Vendor a2ui-project
Product a2ui
Versions
  • Version 0.9 is affected
  • Version 0.9.1 is affected

Credits

  • colorfullbz (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Resource Consumption CWE
  • Denial of Service CWE