Denial of Service Vulnerability in SmallRye GraphQL Affects Red Hat
CVE-2026-76763

7.5HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
31 August 2026

What is CVE-2026-76763?

A significant flaw in SmallRye GraphQL allows an unauthenticated remote attacker to exploit improper scalar coercion for BigInteger objects. Specifically, this vulnerability arises from inadequate validation of float or string inputs, which permits the use of excessively large exponent float literals in GraphQL queries. When exploited, this can lead to the allocation of abnormally large BigInteger instances, inciting CPU exhaustion or triggering an OutOfMemoryError. Consequently, the affected systems may experience a denial of service, impacting functionality and accessibility.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Arpit Jain for reporting this issue.
.