Sceawere
Vulnerability Detail
CVE-2026-108681UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CowAgent Web Console Denial-of-Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- zhayujie
- Product
- CowAgent
- Attack Type
- Denial of Service
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in zhayujie CowAgent up to 2.1.7. Impacted is an unknown function of the file channel/web/web_channel.py of the component Web Console. The manipulation of the argument session_id results in denial of service. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. Version 2.1.7 (commit dec28324) only partly mitigates via a 512MB body cap. The vendor was contacted early about this disclosure.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T14:17:03.220Z",
"pubdate": "2026-10-11T14:17:03.220Z",
"executiveSummary": "A critical denial-of-service (DoS) vulnerability exists in the zhayujie CowAgent Web Console, specifically within the web_channel.py module.\nThe vulnerability allows remote, unauthenticated attackers to disrupt service availability by manipulating the session_id argument.\nAffected versions include all releases up to and including 2.1.7.\nWhile version 2.1.7 introduced a 512MB body size limitation, this measure is insufficient to fully remediate the underlying flaw.\nThe existence of public exploit code significantly elevates the risk profile, enabling potential adversaries to easily incapacitate affected systems.\nThe flaw stems from improper handling of the session_id parameter during request processing, which can lead to resource exhaustion or service crashing.\nGiven the remote nature of the vulnerability, it represents a substantial threat to the availability and operational integrity of CowAgent instances.",
"technicalDetails": "The vulnerability resides in the channel/web/web_channel.py component of the CowAgent Web Console. The root cause is an insecure handling mechanism of the session_id parameter during the ingestion of web requests.\nAn attacker can exploit this flaw by sending specifically crafted, malicious payloads targeting the session_id argument. Because the application logic fails to properly validate or sanitize this input before processing, it triggers an abnormal state that results in a service-wide denial of service.\nThe attack vector is remote, requiring no prior authentication or administrative privileges to execute. This network-exposed entry point allows an attacker to send high-volume or malformed requests that overwhelm the process, causing the Web Console to hang, crash, or enter an unresponsive state.\nVersion 2.1.7 (commit dec28324) attempted to mitigate the issue by implementing a 512MB body size cap. This mechanism is conceptually insufficient because it merely restricts the total volume of data transmitted in the request body but does not address the fundamental logic error in how the web_channel.py component parses the session_id parameter.\nThe exploitation flow follows these steps: 1) The attacker identifies a targetable instance of the CowAgent Web Console accessible over the network. 2) The attacker crafts an HTTP request containing a malicious session_id payload designed to trigger the vulnerable code path within web_channel.py. 3) The application attempts to parse this identifier without sufficient bounds checking or validation logic. 4) The resulting processing error causes the execution thread to fail, leading to resource exhaustion or a segmentation fault that disrupts service availability for legitimate users.\nBecause public exploit code is available, the barrier to entry is extremely low, allowing attackers to weaponize this DoS condition to force service outages effectively."
}