Junglewise Threat Intelligence

CVE-2026-9165: Red Hat Advanced Cluster Security unbounded GraphQL query depth in Central

CVE-2026-9165 · Severity: high · CVSS 7.7 · Published 2026-07-06

Vendors: Red Hat.

Executive brief

A security vulnerability exists in Red Hat Advanced Cluster Security for Kubernetes (RHACS), a platform used to secure containerized environments. An authorized user can send specially crafted, complex requests to the management console that overwhelm the system's resources. This can lead to a denial of service, making the security management interface unavailable to administrators.

Technical details

A resource exhaustion vulnerability (CWE-400) exists in the RHACS Central GraphQL API (/api/graphql). The application fails to enforce a maximum query depth when processing requests against a schema that contains recursive type relationships. An authenticated attacker with a valid API token can exploit this by submitting deeply nested GraphQL queries. This results in excessive resolver and database activity, leading to high CPU and memory utilization and a subsequent denial of service (DoS) of the Central management component. The vulnerability is tracked as CVE-2026-9165.

Affected products

  • Red Hat Advanced Cluster Security 4 4

Timeline

  • 2026-05-21: disclosed: Initial report in Red Hat Bugzilla
  • 2026-07-06: advisory: NVD and Red Hat published advisory details

References