Red HatCVE-2026-76763
Red Hat build of Quarkus: denial of service
High7.5CVE-2026-76763 · Published Aug 31, 2026 · updated Sep 1, 2026
A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An unauthenticated remote attacker can exploit this by sending a GraphQL query containing a large exponent float literal. This can lead to the allocation of extremely large BigInteger objects, causing CPU exhaustion or an OutOfMemoryError, resulting in a denial of service.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat build of Quarkus Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-1284
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 1 | Red Hat popt. This vulnerability: memory corruption | Low2.5 | No fix yet |
| Aug 31 | Red Hat WebKitGTK: memory corruption | High8.8 | No fix yet |
| Aug 31 | Red Hat GDB: out-of-bounds write | High7.0 | No fix yet |
| Aug 31 | Red Hat RESTEasy: XML external entity | High7.5 | No fix yet |
| Aug 31 | Red Hat Qute template engine: template injection | High8.8 | 3.27.5.SP1+1 more |
| Aug 31 | Red Hat Enterprise Linux 10: resource exhaustion | High7.5 | No fix yet |