<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T16:43:40.048293+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-309318</id>
    <title>EUVD-2026-309318</title>
    <updated>2026-10-08T16:43:40.097273+00:00</updated>
    <content>EUVD-2026-309318</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-309318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42793</id>
    <title>fkie_cve-2026-42793</title>
    <updated>2026-10-08T16:43:40.097309+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service via atom table exhaustion when parsing attacker-controlled GraphQL SDL.</p>
<p>Multiple Blueprint.Draft.convert/2 implementations in Absinthe's SDL language modules call String.to_atom/1 on attacker-controlled names from parsed GraphQL SDL documents, including directive names, field names, type names, and argument names. Because atoms are never garbage-collected and the BEAM atom table has a fixed limit (default 1,048,576), each unique name permanently consumes one slot. An attacker can exhaust the atom table by submitting SDL documents containing enough unique names, causing the Erlang VM to abort with system_limit and taking down the entire node.</p>
<p>Any application that passes attacker-controlled GraphQL SDL through Absinthe's parser is exposed — for example, a schema-upload endpoint, a federation gateway that ingests remote SDL, or any developer tool that runs the parser over user-supplied documents.</p>
<p>This issue affects absinthe: from 1.5.0 before 1.10.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42793"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qf4g-9fqq-mmm7</id>
    <title>GHSA-qf4g-9fqq-mmm7 — Absinthe: Unbounded atom creation from parsed directive name</title>
    <updated>2026-10-08T16:43:40.097355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Hex: absinthe</p>
<p>### Summary
When Absinthe parses a GraphQL SDL document, every `directive @&lt;name&gt;` definition is converted into a freshly created atom without any allow-list or length cap. Because atoms are never garbage-collected and the BEAM has a hard ~1,048,576 atom-table limit, any application that feeds attacker-controlled SDL through Absinthe's parser can be crashed (whole VM termination) by submitting a document containing enough unique directive names.</p>
<p>Introduced in https://github.com/absinthe-graphql/absinthe/commit/d0eae7764520d4e8e5dfff619068c0de911aec33</p>
<p>### Details
In `lib/absinthe/language/directive_definition.ex:27`, the `Blueprint.from_ast/2` conversion does:</p>
<p>```elixir
Macro.underscore(node.name) |&gt; String.to_atom()
```</p>
<p>`node.name` is taken verbatim from the parsed GraphQL document, so the atom is created before the directive has been validated against any known schema. There is no use of `String.to_existing_atom/1`, no length cap, and no allow-list. Each unique directive name in the input permanently consumes one slot in the global atom table.</p>
<p>Any code path that runs `Absinthe.Phase.Parse` (or any equivalent that ultimately calls `Absinthe.Blueprint.Draft.convert/2` on a parsed `DirectiveDefinition` node) on untrusted text is exposed — for example, a schema-upload endpoint, a federation gateway that ingests remote SDL, an introspection-to-SDL converter, or any developer tool that runs the parser over user-supplied documents. An attacker only needs to submit one (or a h…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qf4g-9fqq-mmm7"/>
  </entry>
</feed>
