Description
A vulnerability has been found in birkir prime up to 0.4.0.beta.0. The affected element is an unknown function of the file /graphql of the component GraphQL Directive Handler. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-01-19
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Monitor
AI Analysis

Impact

A vulnerability exists in the GraphQL Directive Handler component of birkir prime that allows an attacker to trigger a denial‑of‑service condition by manipulating an unknown function in the /graphql file. Remote exploitation is possible; the attack can cause the application to become unresponsive, impacting service availability for all users.

Affected Systems

birkir:prime version 0.4.0.beta.0 and any earlier releases are affected. The issue has been reported to the vendor but no fix has been released as of the advisory date.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate to high severity. The EPSS score is below 1 %, implying a low probability of active exploitation, and the vulnerability is not listed in CISA’s KEV catalog. However, because the vulnerability is remotely exploitable and can halt the service, it poses a significant risk to availability. Attackers may send crafted GraphQL queries to trigger the denial‑of‑service, potentially disrupting business operations.

Generated by OpenCVE AI on April 18, 2026 at 15:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • If an immediate upgrade is not possible, block or rate‑limit access to the /graphql endpoint from untrusted networks to reduce the attack surface.
  • Apply application‑level input validation or a firewall rule that rejects malformed GraphQL requests.
  • Monitor application logs for repeated failed or slow GraphQL requests and alert for potential abuse.

Generated by OpenCVE AI on April 18, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
References

Wed, 04 Feb 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:birkir:prime:*:*:*:*:*:*:*:*

Tue, 20 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Birkir
Birkir prime
Vendors & Products Birkir
Birkir prime

Mon, 19 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in birkir prime up to 0.4.0.beta.0. The affected element is an unknown function of the file /graphql of the component GraphQL Directive Handler. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title birkir prime GraphQL Directive graphql denial of service
Weaknesses CWE-404
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:48:31.003Z

Reserved: 2026-01-19T07:15:36.664Z

Link: CVE-2026-1172

cve-icon Vulnrichment

Updated: 2026-01-20T17:31:07.735Z

cve-icon NVD

Status : Modified

Published: 2026-01-19T19:16:03.553

Modified: 2026-02-23T09:16:49.310

Link: CVE-2026-1172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T16:00:04Z

Weaknesses