Red HatCVE-2026-9165
Red Hat Advanced Cluster Security 4: denial of service
High7.7CVE-2026-9165 · Published Jul 6, 2026 · updated Sep 8, 2026
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Advanced Cluster Security 4 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-400
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 7 | Red Hat SSSD: path traversal | High8.0 | No fix yet |
| Jul 7 | Red Hat SSSD: insecure default | High8.8 | No fix yet |
| Jul 7 | Red Hat GIMP: integer overflow | High7.3 | No fix yet |
| Jul 6 | Red Hat GIMP. The PlayStation TIM loader: integer overflow | Medium5.5 | No fix yet |
| Jul 6 | Red Hat GIMP: memory corruption | High7.3 | No fix yet |
| Jul 5 | A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker... | Medium4.8 | No fix yet |