Impact
A vulnerability exists in the GraphQL Directive Handler component of birkir prime that allows an attacker to trigger a denial‑of‑service condition by manipulating an unknown function in the /graphql file. Remote exploitation is possible; the attack can cause the application to become unresponsive, impacting service availability for all users.
Affected Systems
birkir:prime version 0.4.0.beta.0 and any earlier releases are affected. The issue has been reported to the vendor but no fix has been released as of the advisory date.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate to high severity. The EPSS score is below 1 %, implying a low probability of active exploitation, and the vulnerability is not listed in CISA’s KEV catalog. However, because the vulnerability is remotely exploitable and can halt the service, it poses a significant risk to availability. Attackers may send crafted GraphQL queries to trigger the denial‑of‑service, potentially disrupting business operations.
OpenCVE Enrichment