Description
A vulnerability was determined in birkir prime up to 0.4.0.beta.0. This affects an unknown function of the file /graphql of the component GraphQL Alias Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-01-19
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service through uncontrolled resource consumption
Action: Assess Impact
AI Analysis

Impact

The flaw resides in the GraphQL Alias Handler of birkir prime and allows an attacker to craft requests that trigger excessive resource usage, leading to a denial of service scenario where memory or processing capacity is exhausted. This impacts the availability of the service, potentially affecting all users that rely on the GraphQL endpoint. The weakness is classified under uncontrolled resource consumption (CWE‑400) and resource shortage (CWE‑404).

Affected Systems

The vulnerability affects birkir prime versions up to 0.4.0.beta.0, specifically the /graphql component that implements the GraphQL Alias Handler. No later versions are acknowledged in the supplied data.

Risk and Exploitability

The CVSS score of 6.9 places the vulnerability in the medium severity range, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack can be carried out remotely over the network, as disclosures exist, yet documented incidents are unknown. Mitigation can be achieved by restricting access to the GraphQL endpoint or applying additional controls, as no official patch is available.

Generated by OpenCVE AI on April 18, 2026 at 15:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade birkir prime to a release newer than 0.4.0.beta.0 once available
  • Implement rate limiting or throttling on the GraphQL endpoint to cap concurrent requests
  • Enforce query depth limits or other input validation techniques to restrict the size of requests processed by the GraphQL server

Generated by OpenCVE AI on April 18, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
References

Wed, 04 Feb 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:birkir:prime:*:*:*:*:*:*:*:*

Tue, 20 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Birkir
Birkir prime
Vendors & Products Birkir
Birkir prime

Mon, 19 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in birkir prime up to 0.4.0.beta.0. This affects an unknown function of the file /graphql of the component GraphQL Alias Handler. This manipulation causes resource consumption. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Title birkir prime GraphQL Alias graphql resource consumption
Weaknesses CWE-400
CWE-404
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:48:57.030Z

Reserved: 2026-01-19T07:15:42.177Z

Link: CVE-2026-1174

cve-icon Vulnrichment

Updated: 2026-01-20T14:44:58.966Z

cve-icon NVD

Status : Modified

Published: 2026-01-19T20:15:48.930

Modified: 2026-02-23T09:16:49.650

Link: CVE-2026-1174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T16:00:04Z

Weaknesses