CVE-2026-9165 Details
Description
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.
A denial-of-service vulnerability has been identified in Red Hat Advanced Cluster Security for Kubernetes (RHACS) Central. The issue arises because the authenticated GraphQL API does not limit the depth of queries. This allows an authenticated user with a valid API token to send deeply nested queries that consume excessive resources, disrupting the availability of the Central management plane.
Users are advised to monitor for updates addressing this vulnerability, which will be released according to the RHACS support lifecycle. Consult the associated errata for affected versions and update instructions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | [email protected] |
| Aug 17, 2026 | CVE Modified | [email protected] |
| Aug 16, 2026 | CVE Modified | [email protected] |
| Aug 16, 2026 | CVE Modified | [email protected] |
| Aug 13, 2026 | CVE Modified | [email protected] |
| Jul 19, 2026 | CVE Modified | [email protected] |
| Jul 8, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | CVE Modified | [email protected] |
| Jul 7, 2026 | CVE Modified | CISA-ADP |
| Jul 6, 2026 | CVE Translated | [email protected] |
| Jul 6, 2026 | New CVE Received | [email protected] |