PatchSiren cyber security CVE debrief
CVE-2026-81636 ash-project CVE debrief
The CVE-2026-81636 vulnerability in ash_graphql allows an unauthenticated client to bypass the GraphQL query-complexity limit, potentially leading to an unbounded database read. This issue affects ash_graphql versions from 0.16.23 before 1.11.0. The fix adds first and last clauses clamped to the action's page size. Organizations using ash_graphql should prioritize patching and monitoring to prevent potential high-severity attacks. The CVE record was published on 2026-08-30T19:17:29.543Z and has not been modified since then. The vulnerability has a CVSS score of 8.7 and is classified as HIGH severity.
- Vendor
- ash-project
- Product
- ash_graphql
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-30
- Original CVE updated
- 2026-08-30
- Advisory published
- 2026-08-30
- Advisory updated
- 2026-08-30
Who should care
Organizations using ash_graphql, especially those with high-severity GraphQL query complexity, should prioritize patching and monitoring to prevent potential attacks. This includes reviewing and updating vulnerable ash_graphql instances, implementing compensating controls, and conducting inventory checks to identify and update vulnerable ash_graphql instances. Security teams and vulnerability management teams should also review the CVE record and assess the potential impact on their organization. Additionally, operators and platform teams should be aware of the potential risks and take necessary precautions to prevent exploitation. The vulnerability has a high CVSS score of 8.7, indicating a high severity level. Therefore, it is essential for organizations to take immediate action to mitigate the vulnerability and prevent potential attacks. This may involve applying patches, implementing compensating controls, and conducting thorough reviews of their systems and networks to identify and address any potential vulnerabilities. By taking proactive steps, organizations can reduce the risk of exploitation and protect their systems and data from potential attacks. The CVE record provides detailed information on the vulnerability, including its description, CVSS score, and affected versions. Organizations should review this information carefully and take necessary actions to ensure the security and integrity of their systems and data. The vulnerability affects ash_graphql versions from 0.16.23 before 1.11.0, and the fix adds first and last clauses clamped to the action's page size. The vulnerability has a significant impact on the security and integrity of systems and data, and organizations should prioritize patching and monitoring to prevent potential attacks. The CVE record was published on 2026-08-30T19:17:29.543Z and has not been modified since then. The vulnerability is classified as HIGH severity, and organizations should take immediate action to mitigate the vulnerability and prevent potential attacks. The vulnerability allows an unauthenticated client to bypass the GraphQL query-complexity limit, potentially leading to an unbounded database read. The fix adds
Technical summary
The CVE-2026-81636 vulnerability in ash_graphql allows an unauthenticated client to bypass the GraphQL query-complexity limit, potentially leading to an unbounded database read. This issue affects ash_graphql versions from 0.16.23 before 1.11.0. The fix adds first and last clauses clamped to the action's page size. The vulnerability is caused by a multiplication of child complexity by the requested page size only when the argument map contains :limit (offset pagination). Relay connections and keyset pagination use first and last, which never match that clause and fall through to the catch-all that returns child_complexity + 1.
Defensive priority
Organizations using ash_graphql should prioritize patching to prevent potential high-severity attacks.
Recommended defensive actions
- Apply patches for ash_graphql versions between 0.16.23 and before 1.11.0.
- Implement compensating controls to monitor and limit GraphQL query complexity.
- Conduct inventory checks to identify and update vulnerable ash_graphql instances.
- Review and update vulnerable ash_graphql instances.
- Implement monitoring to detect potential exploitation attempts.
- Conduct regular security audits to identify and address potential vulnerabilities.
- Track and verify patch deployment for ash_graphql instances.
Evidence notes
The CVE-2026-81636 issue arises from a vulnerability in ash_graphql, allowing an unauthenticated client to bypass the GraphQL query-complexity limit. This could lead to an unbounded database read. The affected versions are from 0.16.23 before 1.11.0. Evidence is based on official CVE and NVD records, as well as references from Erlef and GitHub.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81636 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81636
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81636 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81636
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.erlef.org/cves/CVE-2026-81636.html
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/ash-project/ash_graphql/commit/c3229f6a65cbabb32fd7ffcac881922d1b3b30ad
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://github.com/ash-project/ash_graphql/security/advisories/GHSA-mwc4-r9fc-h6mg
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
-
Source reference
Unverified legacy reference
URL: https://osv.dev/vulnerability/EEF-CVE-2026-81636
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.