Resource Allocation Vulnerability in Ash-Project's Ash GraphQL
CVE-2026-81636
What is CVE-2026-81636?
A resource allocation vulnerability in Ash-Project's Ash GraphQL permits unauthenticated clients to circumvent established query complexity limits. The flaw exists in the query_complexity function, where pagination parameters do not trigger appropriate limits, enabling excessively complex queries that can lead to unbounded database read operations. The vulnerability specifically affects versions from 0.16.23 and prior to 1.11.0, necessitating immediate attention to mitigate risks associated with potential data exposure. This flaw poses significant challenges in maintaining application integrity and performance under malicious query execution.
Affected Version(s)
ash_graphql 0.16.23 < 1.11.0
ash_graphql d8a3e1b15587180ad9cb3ceeb398863d086c163b
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
