Description
A flaw has been found in birkir prime up to 0.4.0.beta.0. Impacted is an unknown function of the file /graphql of the component GraphQL Field Handler. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-01-19
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the GraphQL Field Handler component of birkir prime up to 0.4.0.beta.0. A malicious request targeting an unknown function within /graphql can trigger a denial of service. The flaw allows an attacker to cause the application to exhaust resources, potentially crashing or rendering the service unavailable, which directly impacts availability.

Affected Systems

The affected product is birkir prime from the vendor birkir. All installations that use version 0.4.0.beta.0 or earlier are vulnerable. The exploit has been publicly disclosed in the project's issue tracker and in several vulnerability databases.

Risk and Exploitability

The CVSS base score is 6.9, classifying the risk as medium, while the EPSS score is below 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, and no official patch is yet released. Nonetheless, the attack vector is remote, and the exploit code is available, so the risk is moderate but worth addressing promptly.

Generated by OpenCVE AI on April 18, 2026 at 19:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest birkir prime release that removes the flaw in the GraphQL Field Handler (e.g., a version newer than 0.4.0.beta.0).
  • Until a patched release is available, block or disable the /graphql endpoint or the specific field that triggers the denial of service to prevent remote exploitation.
  • If the endpoint cannot be removed or upgraded, implement rate limiting or request throttling on the /graphql endpoint to reduce the likelihood of a successful denial‑of‑service attack.

Generated by OpenCVE AI on April 18, 2026 at 19:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
References

Wed, 04 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:birkir:prime:*:*:*:*:*:*:*:*

Tue, 20 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Birkir
Birkir prime
Vendors & Products Birkir
Birkir prime

Mon, 19 Jan 2026 18:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in birkir prime up to 0.4.0.beta.0. Impacted is an unknown function of the file /graphql of the component GraphQL Field Handler. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title birkir prime GraphQL Field graphql denial of service
Weaknesses CWE-404
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:48:18.220Z

Reserved: 2026-01-19T07:15:33.734Z

Link: CVE-2026-1171

cve-icon Vulnrichment

Updated: 2026-01-20T17:28:46.665Z

cve-icon NVD

Status : Modified

Published: 2026-01-19T19:16:03.373

Modified: 2026-02-23T09:16:49.120

Link: CVE-2026-1171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T19:15:10Z

Weaknesses