Impact
The flaw resides in the GraphQL Alias Handler of birkir prime and allows an attacker to craft requests that trigger excessive resource usage, leading to a denial of service scenario where memory or processing capacity is exhausted. This impacts the availability of the service, potentially affecting all users that rely on the GraphQL endpoint. The weakness is classified under uncontrolled resource consumption (CWE‑400) and resource shortage (CWE‑404).
Affected Systems
The vulnerability affects birkir prime versions up to 0.4.0.beta.0, specifically the /graphql component that implements the GraphQL Alias Handler. No later versions are acknowledged in the supplied data.
Risk and Exploitability
The CVSS score of 6.9 places the vulnerability in the medium severity range, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack can be carried out remotely over the network, as disclosures exist, yet documented incidents are unknown. Mitigation can be achieved by restricting access to the GraphQL endpoint or applying additional controls, as no official patch is available.
OpenCVE Enrichment