Description
Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted _entities representation keys.

Every key of every object in the representations argument of the federation-mandated _entities field is converted with String.to_atom/1 by convert_key/2 in lib/absinthe/federation/schema/entities_field.ex. representations is typed as the open-ended _Any scalar, so its keys bypass schema coercion and the attacker names them freely. Atoms are never garbage collected and the BEAM atom table is hard-capped (about 1,048,576 entries by default), so one request carrying tens of thousands of unique keys creates that many permanent atoms and a handful of such requests exhausts the table and aborts the node. The impact is confined to availability: no data is read or altered, and recovery requires restarting the application.

This issue affects absinthe_federation: from 0.1.0 before 0.9.3.
Published: 2026-08-07
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated remote attacker to exhaust the BEAM atom table by supplying a large number of unique keys in the _entities representation field. Allocation of resources without limits or throttling leads to the Erlang VM aborting, resulting in a denial of service. The weakness is a classic case of unchecked atom allocation, identified by CWE-770. No data is read or modified; the impact is strictly disruption of service.

Affected Systems

DivvyPayHQ absinthe_federation, versions 0.1.0 through 0.9.2 inclusive. Version 0.9.3 and later are unaffected.

Risk and Exploitability

The exposure scores a high CVSS of 8.7 and currently has no EPSS value reported, indicating the exploitation probability is not quantified but remains a concern. The vulnerability is not listed in the CISA KEV catalog. Attackers need only send crafted GraphQL requests targeting the _entities field; authentication is not required, making the attack surface wide. Once triggered, the node terminates and requires a restart, leading to significant downtime.

Generated by OpenCVE AI on August 7, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade DivvyPayHQ absinthe_federation to version 0.9.3 or newer
  • If upgrading is not feasible, limit the number of unique keys allowed in the _entities representation field, for example by enforcing a maximum payload size or maximum number of keys
  • Apply rate limiting or authentication to the GraphQL endpoint to reduce repeated exploit attempts

Generated by OpenCVE AI on August 7, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted _entities representation keys. Every key of every object in the representations argument of the federation-mandated _entities field is converted with String.to_atom/1 by convert_key/2 in lib/absinthe/federation/schema/entities_field.ex. representations is typed as the open-ended _Any scalar, so its keys bypass schema coercion and the attacker names them freely. Atoms are never garbage collected and the BEAM atom table is hard-capped (about 1,048,576 entries by default), so one request carrying tens of thousands of unique keys creates that many permanent atoms and a handful of such requests exhausts the table and aborts the node. The impact is confined to availability: no data is read or altered, and recovery requires restarting the application. This issue affects absinthe_federation: from 0.1.0 before 0.9.3.
Title Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
First Time appeared Divvypayhq
Divvypayhq absinthe Federation
Weaknesses CWE-770
CPEs cpe:2.3:a:divvypayhq:absinthe_federation:*:*:*:*:*:*:*:*
Vendors & Products Divvypayhq
Divvypayhq absinthe Federation
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Divvypayhq Absinthe Federation
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-08-07T18:12:59.050Z

Reserved: 2026-08-07T10:15:01.514Z

Link: CVE-2026-67585

cve-icon Vulnrichment

Updated: 2026-08-07T18:12:55.121Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T17:30:16Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling