CVE-2026-40115General(praison / praisonai)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire HTTP request body into memory based on the client-supplied Content-Length header with no upper bound. Combined with authentication being disabled by default (no token configured), any local process can send arbitrarily large POST requests to exhaust server memory and cause a denial of service. The Starlette-based server (serve.py) has RequestSizeLimitMiddleware with a 10MB limit, but the WSGI server lacks any equivalent protection. This vulnerability is fixed in 4.5.128.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-10: 3Technical Details · 2026-04-10: 204-10
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-40115 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (http://server.py) reads the entire HTTP request body into memory based on t… https://www.cve.org/CVERecord?id=CVE-2026-40115 ----- Traducción: CVE-… http://infoflow.cloud`

    Post summary

    CVE-2026-40115 affects PraisonAI’s WSGI recipe registry, where the server reads the full HTTP request body into memory prior to v4.5.128, yet the post provides no PoC, exploit, patch details, or evidence of active exploitation.

    0000029
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40115 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (http://server.py) reads the entire HTTP request body into memory based on t… https://www.cve.org/CVERecord?id=CVE-2026-40115

    Post summary

    The snippet references CVE-2026-40115, noting a memory-handling issue in a WSGI registry server, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000154
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40115 Denial of Service via Unbounded Memory Consumption in PraisonAI WSGI Server https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40115

    Post summary

    The text merely lists a CVE and its headline, providing no additional technical or operational details.

    0000043
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more