Description
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.
Published: 2026-07-06
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Red Hat Advanced Cluster Security for Kubernetes allows an authenticated user to submit GraphQL queries of arbitrary depth to the Central service. Because no depth limit is enforced, these deeply nested queries consume excessive CPU and memory resources, leading to a denial of service in the management plane.

Affected Systems

Affected installations are Red Hat Advanced Cluster Security for Kubernetes version 4.9 on EL 8, version 4.10 on EL 8, and version 4.11 on EL 9, as identified by the vendor through their errata listings. All installations running these specific versions are vulnerable.

Risk and Exploitability

The CVSS base score of 7.7 indicates a moderate to high severity. The EPSS score of < 1 % reflects a very low probability of exploitation under current conditions the vulnerability is not listed in CISA’s KEV catalog. An attacker must first obtain an authenticated API token; no known unauthenticated or remote code execution exploits are described. The likely attack vector is an authenticated user exploiting the API to submit a deep GraphQL query that exhausts Central’s resources, potentially disrupting Kubernetes cluster management for the organization.

Generated by OpenCVE AI on July 25, 2026 at 21:02 UTC.

Remediation

Vendor Workaround

There is no complete mitigation other than installing the update once available.


OpenCVE Recommended Actions

  • Apply the vendor patch for Red Hat Advanced Cluster Security to fix the unbounded GraphQL query depth flaw.
  • Limit the issuance and use of API tokens to the minimum set of users who truly require access, and disable tokens no longer needed.
  • Monitor Central for unusually deep GraphQL queries or high CPU/memory consumption; enforce a temporary depth limit or reject requests that exceed a safe threshold if possible.

Generated by OpenCVE AI on July 25, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:advanced_cluster_security:4.10::el8
References

Tue, 07 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:advanced_cluster_security:4.11::el9
References

Tue, 07 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:advanced_cluster_security:4 cpe:/a:redhat:advanced_cluster_security:4.9::el8
References

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 06 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.
Title Stackrox: stackrox: unbounded graphql query depth allows authenticated denial of service
First Time appeared Redhat
Redhat advanced Cluster Security
Weaknesses CWE-400
CPEs cpe:/a:redhat:advanced_cluster_security:4
Vendors & Products Redhat
Redhat advanced Cluster Security
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Redhat Advanced Cluster Security
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-19T00:11:39.889Z

Reserved: 2026-05-21T12:54:16.202Z

Link: CVE-2026-9165

cve-icon Vulnrichment

Updated: 2026-07-07T14:01:03.661Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-06T08:38:30Z

Links: CVE-2026-9165 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T21:15:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption