← All Advisories

Authenticated RHACS API Token Holder Can Exhaust Central Resources with Unbounded GraphQL Query Depth

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-9165

Key Details

CVECVE-2026-9165
CVSS Score / Version7.7 (High) / CVSS v3.1
Updated2026-09-08
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is none; integrity impact is none; availability impact is high.
Classified asCWE-400 (Uncontrolled Resource Consumption)

What to Know

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-9165
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-9165