GraphQL Resource Exhaustion Vulnerability in Keystone CMS
CVE-2026-63421
7.5HIGH
What is CVE-2026-63421?
Keystone, a popular content management system for Node.js, contains a vulnerability in its GraphQL implementation that could lead to resource exhaustion. Prior to version 6.5.3, the findMany resolver improperly compares the signed take argument, enabling remote unauthenticated GraphQL clients to specify a negative take value exceeding the permitted limits. This bypass is also applicable to relationship queries, allowing attackers to retrieve more records than intended, potentially draining server resources and disrupting service availability. Users are advised to upgrade to version 6.5.3 or later to mitigate this risk.
Affected Version(s)
keystone < 6.5.3
