Impact
The vulnerability resides in the GraphQL Field Handler component of birkir prime up to 0.4.0.beta.0. A malicious request targeting an unknown function within /graphql can trigger a denial of service. The flaw allows an attacker to cause the application to exhaust resources, potentially crashing or rendering the service unavailable, which directly impacts availability.
Affected Systems
The affected product is birkir prime from the vendor birkir. All installations that use version 0.4.0.beta.0 or earlier are vulnerable. The exploit has been publicly disclosed in the project's issue tracker and in several vulnerability databases.
Risk and Exploitability
The CVSS base score is 6.9, classifying the risk as medium, while the EPSS score is below 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, and no official patch is yet released. Nonetheless, the attack vector is remote, and the exploit code is available, so the risk is moderate but worth addressing promptly.
OpenCVE Enrichment