GraphQL Resource Exhaustion Vulnerability in Keystone CMS
CVE-2026-63421

7.5HIGH

Key Information:

Vendor

Keystonejs

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-63421?

Keystone, a popular content management system for Node.js, contains a vulnerability in its GraphQL implementation that could lead to resource exhaustion. Prior to version 6.5.3, the findMany resolver improperly compares the signed take argument, enabling remote unauthenticated GraphQL clients to specify a negative take value exceeding the permitted limits. This bypass is also applicable to relationship queries, allowing attackers to retrieve more records than intended, potentially draining server resources and disrupting service availability. Users are advised to upgrade to version 6.5.3 or later to mitigate this risk.

Affected Version(s)

keystone < 6.5.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.