Executive brief
A security vulnerability exists in Red Hat Advanced Cluster Security for Kubernetes (RHACS), a platform used to secure containerized environments. An authorized user can send specially crafted, complex requests to the management console that overwhelm the system's resources. This can lead to a denial of service, making the security management interface unavailable to administrators.
Technical details
A resource exhaustion vulnerability (CWE-400) exists in the RHACS Central GraphQL API (/api/graphql). The application fails to enforce a maximum query depth when processing requests against a schema that contains recursive type relationships. An authenticated attacker with a valid API token can exploit this by submitting deeply nested GraphQL queries. This results in excessive resolver and database activity, leading to high CPU and memory utilization and a subsequent denial of service (DoS) of the Central management component. The vulnerability is tracked as CVE-2026-9165.
Affected products
- Red Hat Advanced Cluster Security 4 4
Timeline
- 2026-05-21: disclosed: Initial report in Red Hat Bugzilla
- 2026-07-06: advisory: NVD and Red Hat published advisory details