ag-ui-protocol / ag-ui-protocol/ag-ui

[BUG]: Kotlin community SDK: StackOverflowError escapes `catch(Exception)`; unbounded accumulators in several community SDKs

Offen
#2,442 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Python
Sterne
15.9k
Forks
1.4k
Ø Merge
1 T. 17 Std.
Gemergte PRs (30 T.)
163

Beschreibung

# Kotlin community SDK: StackOverflowError escapes `catch(Exception)`; unbounded accumulators in several community SDKs

Repository: https://github.com/ag-ui-protocol/ag-ui
Affected: community Kotlin SDK (`SseParser.kt:28-37`) and related items listed below
CWE: CWE-755 (Improper Handling of Exceptional Conditions), CWE-400 (Uncontrolled Resource Consumption)

## Summary (Kotlin)

Event JSON is parsed with kotlinx.serialization without a depth limit. Deeply nested JSON throws `StackOverflowError` — an `Error`, not an `Exception` — which escapes the parser's `catch(Exception)` handler and terminates the JVM/Android process.

## Related unbounded-accumulation items (CWE-400)

- Java client — `HttpAgent.java:107`: no bound on line length
- Dart — data-size cap checked only after accumulation begins (ordering gap)
- Kotlin — tool-call argument and reasoning-content accumulators unbounded
- Rust — UTF-8 sequences split across chunk boundaries mishandled

## Impact

Process termination (Kotlin stack-overflow path) or gradual unbounded memory growth (the accumulation items), triggered by a malicious or misbehaving agent endpoint. Availability only.

## Suggested remediation

- Catch `Throwable` (or `Error`) around parsing, or enforce a parse-depth limit before decoding.
- Apply the Dart SDK's reference cap set (event/id/data size, total budget) across the community SDKs.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.