{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/smallrye/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:smallrye:graphql:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-76763"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GraphQL"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","graphql"],"_cs_type":"advisory","_cs_vendors":["SmallRye"],"content_html":"\u003cp\u003eA high-severity vulnerability (CVE-2026-76763) has been identified in the SmallRye GraphQL implementation. The flaw exists within the number scalar coercion logic for BigInteger objects, which fails to adequately validate the magnitude of float or string inputs provided during query processing. An unauthenticated remote attacker can exploit this weakness by crafting a malicious GraphQL query containing an exceptionally large exponent float literal. When processed by the application, this input forces the system to allocate massive BigInteger objects, leading to uncontrolled CPU consumption or an OutOfMemoryError (OOME). This exploitation effectively crashes the service or degrades performance to the point of a denial of service, impacting availability for all users of the affected GraphQL endpoint.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in a denial of service for any application utilizing the vulnerable SmallRye GraphQL library. This can lead to service outages and instability, potentially affecting all sectors that rely on this library for GraphQL API operations. Given the ease of delivery via a standard GraphQL query, the impact on availability is significant for internet-facing APIs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and operations teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all internal and external-facing applications utilizing the SmallRye GraphQL library.\u003c/li\u003e\n\u003cli\u003eMonitor application logs and infrastructure metrics for spikes in CPU usage or frequent OutOfMemoryError exceptions following incoming GraphQL requests.\u003c/li\u003e\n\u003cli\u003eReview vendor release notes for the patched version of SmallRye GraphQL and perform a rolling update across the environment.\u003c/li\u003e\n\u003cli\u003eImplement request-size validation and rate limiting on GraphQL endpoints to prevent the processing of abnormally large or malformed query payloads.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T15:58:02Z","date_published":"2026-08-31T15:58:02Z","id":"https://feed.craftedsignal.io/briefs/2026-08-smallrye-graphql-dos/","summary":"An unauthenticated remote attacker can cause a denial of service in SmallRye GraphQL by exploiting improper BigInteger scalar coercion to trigger resource exhaustion.","title":"Denial of Service Vulnerability in SmallRye GraphQL","url":"https://feed.craftedsignal.io/briefs/2026-08-smallrye-graphql-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - SmallRye","version":"https://jsonfeed.org/version/1.1"}