absinthe
1.10.2
GraphQL for Elixir
Current section
2 Advisories
Jump to
Current section
2 Advisories
Quadratic fragment-name uniqueness check causes denial of service in absinthe
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-43967.html
- https://github.com/absinthe-graphql/absinthe
- https://github.com/absinthe-graphql/absinthe/commit/223600c520493dcaf95080af552c413099f92c9d
- https://github.com/absinthe-graphql/absinthe/security/advisories/GHSA-9mhv-8h52-q7q2
- https://hex.pm/packages/absinthe
- https://nvd.nist.gov/vuln/detail/CVE-2026-43967
- https://osv.dev/vulnerability/EEF-CVE-2026-43967
Atom table exhaustion via attacker-controlled GraphQL SDL names in absinthe
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-42793.html
- https://github.com/absinthe-graphql/absinthe
- https://github.com/absinthe-graphql/absinthe/commit/dd842b938e3823f345c10416914ffab5d5536838
- https://github.com/absinthe-graphql/absinthe/security/advisories/GHSA-qf4g-9fqq-mmm7
- https://hex.pm/packages/absinthe
- https://nvd.nist.gov/vuln/detail/CVE-2026-42793
- https://osv.dev/vulnerability/EEF-CVE-2026-42793
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
53 132
yesterday
11 522
last 7 days
56 578
all time
46 328 361