CVE-2026-67585

HIGH CVSS 4.0: 8.7 EPSS 0.41%
Updated Aug 12, 2026
Divvypayhq
Parameter Value
CVSS 8.7 (HIGH)
Affected Versions 0.1.0 — 0.9.3
Fixed In 0.9.3
Type CWE-770 (Allocation Without Limits)
Vendor Divvypayhq
Public PoC No

Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted _entities representation keys. Every key of every object in the representations argument of the federation-mandated _entities field is converted with String.to_atom/1 by convert_key/2 in lib/absinthe/federation/schema/entities_field.ex. representations is typed as the open-ended _Any scalar, so its keys bypass schema coercion and the attacker names them freely. Atoms are never garbage collected and the BEAM atom table is hard-capped (about 1,048,576 entries by default), so one request carrying tens of thousands of unique keys creates that many permanent atoms and a handful of such requests exhausts the table and aborts the node.

The impact is confined to availability: no data is read or altered, and recovery requires restarting the application. This issue affects absinthe_federation: from 0.1.0 before 0.9.3.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Divvypayhq Absinthe_Federation
cpe:2.3:a:divvypayhq:absinthe_federation:*:*:*:*:*:*:*:*
0.1.0 0.9.3