A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.
References
Configurations
No configuration.
History
08 Jul 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
07 Jul 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
07 Jul 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
06 Jul 2026, 10:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
06 Jul 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-06 09:16
Updated : 2026-07-19 01:17
NVD link : CVE-2026-9165
Mitre link : CVE-2026-9165
CVE.ORG link : CVE-2026-9165
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
