PT-2026-93184 · A2Ui · A2Ui

·

CVE-2026-92114

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions a2ui-project a2ui versions prior to 0.10.7
Description A remote attack can be launched against the Basic Catalog component due to inefficient regular expression complexity within an unknown function in the file renderers/web core/src/v0 9/basic catalog/functions/safe regex.ts. This issue can lead to a Regular Expression Denial of Service (ReDoS), where a specially crafted input causes the system to consume excessive resources during processing.
Recommendations Update to a version newer than 0.10.6. As a temporary workaround, restrict access to the functions within the renderers/web core/src/v0 9/basic catalog/functions/safe regex.ts file to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92114

Affected Products

A2Ui