Resource Allocation Vulnerability in DivvyPayHQ's absinthe_federation
CVE-2026-67585
What is CVE-2026-67585?
The absinthe_federation component of DivvyPayHQ has a flaw that enables unauthenticated remote attackers to exhaust the Erlang VM's atom table, potentially leading to application unavailability. The vulnerability arises when the _entities representation keys bypass schema coercion, allowing attackers to create a large number of unique atom keys during requests. Since atom tables in Erlang are fixed in size and not garbage collected, an attacker could craft requests with numerous unique keys, exhausting the available table entries. As a result, the application becomes non-responsive, requiring a restart for recovery. This issue affects versions of absinthe_federation from 0.1.0 before 0.9.3.
Affected Version(s)
absinthe_federation 0.1.0 < 0.9.3
absinthe_federation 640a234a26b2d6fe5d9d21e00e5f4fce5645c0bf
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
