SmallRye GraphQL 中发现了一个缺陷。BigInteger 的标量类型强制转换未能正确验证浮点数或字符串输入的数值大小。未经身份验证的远程攻击者可以通过发送包含大指数浮点数字面量的 GraphQL 查询来利用此缺陷,从而导致分配极大容量的 BigInteger 对象,造成 CPU 资源耗尽或触发 OutOfMemoryError(内存溢出错误),最终导致服务不可用(拒绝服务)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Quarkus | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat build of Quarkus | - |
cpe:/a:redhat:quarkus:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-83596 | 8.8 HIGH | Webkitgtk: validate the full featurelist array once in opentypeverticaldata findfeature |
| CVE-2026-12894 | 8.8 HIGH | Quarkus-qute: io.quarkus.qute.reflectionvalueresolver: quarkus:server-side template inject |
| CVE-2026-13732 | 7.8 HIGH | Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf |
| CVE-2026-17615 | 7.5 HIGH | Resteasy-core: resteasy sourceprovider remote unauthenticated file read |
| CVE-2026-81624 | 7.5 HIGH | Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite |
No comments yet