PT-2026-93691 · A2Ui+1 · A2Ui
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X |
Name of the Vulnerable Software and Affected Versions
a2ui versions 0.9 through 0.9.1
Description
A remote manipulation of the
updateComponents() function within the basic functions.ts file of the Update Components component can lead to excessive resource consumption.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the use of the
updateComponents() function to minimize the risk of exploitation.Exploit
Resource Exhaustion
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
A2Ui