CVE-2026-108768 | zhayujie CowAgent up to 2.2.0 Streaming Tool-Call Argument json.loads allocation of resources
A vulnerability was found in zhayujie CowAgent up to 2.2.0. It has been rated as problematic. Affected by this issue is the function json.loads of the component Streaming Tool-Call Argument Handler. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2026-108768. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More