CVE-2026-8319 Details
Description
A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_relevant_memories_to_working_memory of the file core/cat/looking_glass/stray_cat.py of the component cheshire_cat_core. This manipulation causes resource consumption. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
A denial-of-service vulnerability has been identified in aiwaves-cn agents versions prior to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. The issue resides in the Cheshire Cat Core component, specifically within the 'recall_relevant_memories_to_working_memory' function of 'core/cat/looking_glass/stray_cat.py'. This vulnerability allows remote exploitation by causing excessive resource consumption. The problem arises because the application does not limit the size of incoming messages, enabling attackers to send overly large payloads that disrupt server operations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aiwaves-cn/agents/ | [email protected] | ProductVendor |
| https://github.com/aiwaves-cn/agents/issues/219 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/submit/811274 | [email protected] | Permission Required |
| https://vuldb.com/vuln/362606 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/362606/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aiwaves-cn agents | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | [email protected] |
Volerion