{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-108768", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-10-11T07:20:26.021Z", "datePublished": "2026-10-11T18:59:38.491Z", "dateUpdated": "2026-10-11T18:59:38.491Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-10-11T18:59:38.491Z" }, "title": "zhayujie CowAgent Streaming Tool-Call Argument json.loads allocation of resources", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-770", "lang": "en", "description": "Allocation of Resources" } ] }, { "descriptions": [ { "type": "CWE", "cweId": "CWE-400", "lang": "en", "description": "Resource Consumption" } ] } ], "affected": [ { "vendor": "zhayujie", "product": "CowAgent", "versions": [ { "version": "2.0", "status": "affected" }, { "version": "2.1", "status": "affected" }, { "version": "2.2.0", "status": "affected" } ], "cpes": [ "cpe:2.3:a:zhayujie:cowagent:*:*:*:*:*:*:*:*" ], "modules": [ "Streaming Tool-Call Argument Handler" ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability was identified in zhayujie CowAgent up to 2.2.0. Affected by this issue is the function json.loads of the component Streaming Tool-Call Argument Handler. The manipulation leads to allocation of resources. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 4.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C", "baseSeverity": "MEDIUM" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 4.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C", "baseSeverity": "MEDIUM" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 4, "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:C" } } ], "timeline": [ { "time": "2026-10-11T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-10-11T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-10-11T09:25:37.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "pengguogood (VulDB User)", "type": "reporter" }, { "lang": "en", "value": "VulDB CNA Team", "type": "coordinator" } ], "references": [ { "url": "https://vuldb.com/vuln/416550", "name": "VDB-416550 | zhayujie CowAgent Streaming Tool-Call Argument json.loads allocation of resources", "tags": [ "vdb-entry", "technical-description" ] }, { "url": "https://vuldb.com/vuln/416550/cti", "name": "VDB-416550 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/cve/CVE-2026-108768", "name": "CVE-2026-108768 | CVE Analysis and Report", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/958026", "name": "Submit #958026 | zhayujie CowAgent 2.1.6 Denial of Service", "tags": [ "third-party-advisory" ] }, { "url": "https://github.com/lche511/cve/tree/main/CowAgent_Tool_Call_Arguments_JSON_Repair_DoS_Report", "tags": [ "exploit" ] } ], "x_generator": [ "VulDB PVTS v202610" ] } } }