# Birkir Prime GraphQL 别名资源消耗漏洞
## 概述
birkir prime 在 0.4.0.beta.0 及以下版本中存在一处漏洞,影响 GraphQL Alias Handler 组件的 `/graphql` 文件中某个未知函数,可导致资源消耗。
## 影响版本
birkir prime ≤ 0.4.0.beta.0
## 细节
- 漏洞位于 `/graphql` 文件的 GraphQL Alias Handler 组件中
- 具体涉及的函数未知
- 攻击者可通过远程发送特制请求触发漏洞
- 已有公开披露的利用方式,具备实际利用可能性
## 影响
攻击者可利用该漏洞进行远程攻击,导致系统资源被过度消耗,可能引发服务拒绝(DoS)。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: GraphQL Aliases Overloading Vulnerability · Issue #545 · birkir/prime -- 🔗来源链接
标签:exploitissue-tracking
神龙速读:
## 漏洞关键信息
- **漏洞名称**: GraphQL Aliases Overloading Vulnerability
- **问题编号**: #545
- **状态**: Open
- **描述**:
- 该漏洞允许在单个查询中进行多个相同字段/操作的请求,从而绕过安全限制或导致资源耗尽。
- **PoC(概念验证)**:
- ```bash
curl -X POST -H "User-Agent: oxpecker" -H "Accept-Encoding: gzip, deflate" -H "Accept: */*" -H "Connection:
- ```
标题: CVE-2026-1174 birkir prime GraphQL Alias graphql resource consumption (Issue 545 / EUVD-2026-3196) -- 🔗来源链接
标签:vdb-entry
神龙速读:
### 关键漏洞信息
- **CVE ID**: CVE-2026-1174
- **Vulnerability**: GraphQL Alias resource consumption
- **Affected Versions**: birkir prime up to 0.4.0.beta.0
- **Component**: GraphQL Alias Handler
- **Impact**: Resource exhaustion due to improper handling of unknown function of the `graphql` file
- **Exploit Availability**: Yes (Proof-of-concept)
- **Exploit Price**: $0-$5k
- **CTI Interest Score**: 4.12- (High interest from attackers and security community)
- **CVSS Scores**:
- CVSS v3.1 Base Score: 5.3
- CVSS v2.0 Base Score: 5.0
- **Timeline**:
- 01/19/2026: Advisory disclosed and VulDB entry created/last update
- **Sources**:
- GitHub
- EUVD
- SCIP Labs
### Additional Notes:
- The vulnerability is related to [CWE-400](https://cwe.mitre.org/data/definitions/400.html) which indicates an issue with resource management.
- There is a proof-of-concept available and it can be exploited remotely.
- The vendor `birkir` has been informed but has not responded yet to the issue reported.
暂无评论