Resource Allocation Vulnerability in Ash-Project's Ash GraphQL
CVE-2026-81636

8.7HIGH

Key Information:

Vendor
CVE Published:
30 August 2026

What is CVE-2026-81636?

A resource allocation vulnerability in Ash-Project's Ash GraphQL permits unauthenticated clients to circumvent established query complexity limits. The flaw exists in the query_complexity function, where pagination parameters do not trigger appropriate limits, enabling excessively complex queries that can lead to unbounded database read operations. The vulnerability specifically affects versions from 0.16.23 and prior to 1.11.0, necessitating immediate attention to mitigate risks associated with potential data exposure. This flaw poses significant challenges in maintaining application integrity and performance under malicious query execution.

Affected Version(s)

ash_graphql 0.16.23 < 1.11.0

ash_graphql d8a3e1b15587180ad9cb3ceeb398863d086c163b

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Ullrich
Peter Ullrich
Zach Daniel / Ash Project
Jonatan Männchen / EEF
.