Resource Allocation Vulnerability in DivvyPayHQ's absinthe_federation
CVE-2026-67585

8.7HIGH

Key Information:

Vendor

Divvypayhq

Vendor
CVE Published:
7 August 2026

What is CVE-2026-67585?

The absinthe_federation component of DivvyPayHQ has a flaw that enables unauthenticated remote attackers to exhaust the Erlang VM's atom table, potentially leading to application unavailability. The vulnerability arises when the _entities representation keys bypass schema coercion, allowing attackers to create a large number of unique atom keys during requests. Since atom tables in Erlang are fixed in size and not garbage collected, an attacker could craft requests with numerous unique keys, exhausting the available table entries. As a result, the application becomes non-responsive, requiring a restart for recovery. This issue affects versions of absinthe_federation from 0.1.0 before 0.9.3.

Affected Version(s)

absinthe_federation 0.1.0 < 0.9.3

absinthe_federation 640a234a26b2d6fe5d9d21e00e5f4fce5645c0bf

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Doruk Gurleyen
Jonatan Männchen / EEF
.