Junglewise Threat Intelligence

CVE-2026-42793: Absinthe-graphql DoS via atom table exhaustion in SDL parser

CVE-2026-42793 · Severity: high · CVSS 8.2 · Published 2026-05-08

Executive brief

Absinthe is a popular library used to build GraphQL APIs in Elixir. A vulnerability in how it processes GraphQL schema documents allows an unauthenticated attacker to crash the entire application server. By sending specially crafted documents with many unique names, an attacker can exhaust the server's internal memory for identifiers, leading to a permanent service outage until the system is manually restarted.

Technical details

The vulnerability exists in multiple 'Blueprint.Draft.convert/2' implementations within Absinthe's SDL language modules. The parser calls 'String.to_atom/1' on attacker-controlled names (directives, fields, types, and arguments) from GraphQL Schema Definition Language (SDL) documents. In the Erlang BEAM VM, atoms are not garbage-collected and have a default global limit of 1,048,576. An unauthenticated remote attacker can exhaust this table by submitting SDL documents with a large number of unique names, causing the VM to abort with a 'system_limit' error. This affects any application passing untrusted SDL through Absinthe's parser, such as federation gateways or schema-upload endpoints. The issue is fixed in version 1.10.2.

Affected products

  • absinthe-graphql absinthe from 1.5.0 before 1.10.2

Timeline

  • 2026-05-08: advisory: GHSA-qf4g-9fqq-mmm7 published
  • 2026-05-08: patched: Fixed in version 1.10.2
  • 2026-05-08: disclosed: CVE-2026-42793 published

References

Related threats