[BUG]: Kotlin community SDK: StackOverflowError escapes `catch(Exception)`; unbounded accumulators in several community SDKs
Author: ez-lbzCreated Aug 18, 2026Updated Sep 13, 2026
Kotlin community SDK: StackOverflowError escapes catch(Exception); unbounded accumulators in several community SDKs
Repository: https://github.com/ag-ui-protocol/ag-ui
Affected: community Kotlin SDK (SseParser.kt:28-37) and related items listed below
CWE: CWE-755 (Improper Handling of Exceptional Conditions), CWE-400 (Uncontrolled Resource Consumption)
Summary (Kotlin)
Event JSON is parsed with kotlinx.serialization without a depth limit. Deeply nested JSON throws StackOverflowError — an Error, not an Exception — which escapes the parser's catch(Exception) handler and terminates the JVM/Android process.
Related unbounded-accumulation items (CWE-400)
- Java client —
HttpAgent.java:107: no bound on line length - Dart — data-size cap checked only after accumulation begins (ordering gap)
- Kotlin — tool-call argument and reasoning-content accumulators unbounded
- Rust — UTF-8 sequences split across chunk boundaries mishandled
Impact
Process termination (Kotlin stack-overflow path) or gradual unbounded memory growth (the accumulation items), triggered by a malicious or misbehaving agent endpoint. Availability only.
Suggested remediation
- Catch
Throwable(orError) around parsing, or enforce a parse-depth limit before decoding. - Apply the Dart SDK's reference cap set (event/id/data size, total budget) across the community SDKs.
Source: ag-ui-protocol/ag-ui