Executive brief
ash_graphql is a GraphQL library used to build API servers. A vulnerability allows attackers to bypass rate-limiting controls that prevent expensive database queries. By crafting specific query patterns, an unauthenticated client can force the server to read far more data than intended, potentially causing database overload and service degradation.
Technical details
The vulnerability is a resource-exhaustion flaw in AshGraphql.Graphql.Resolver.query_complexity/3, which calculates GraphQL query cost for complexity-limit enforcement. The function only multiplies child complexity by the requested page size when the :limit argument is present (offset pagination), but fails to account for first and last arguments used in Relay connections and keyset pagination. Nested Relay queries with large first/last values (e.g., posts(first: 500) { edges { node { comments(first: 500) } } }) are incorrectly scored as cheap and bypass Absinthe's max_complexity cap. The fix adds complexity clamping for first and last arguments. No authentication is required; this is a network-accessible denial-of-service vector.
Affected products
- ash-project ash_graphql 0.16.23 to 1.10.x
Timeline
- 2026-08-30: published: CVE-2026-81636 published