Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fw53-q2vg-jr6g

Опубликовано: 06 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.7

Описание

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.

EPSS

Процентиль: 24%
0.00319
Низкий

7.7 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.7
redhat
25 дней назад

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.

CVSS3: 7.7
nvd
25 дней назад

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.

EPSS

Процентиль: 24%
0.00319
Низкий

7.7 High

CVSS3

Дефекты

CWE-400