CVE-2026-10802
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
4.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Vulnerability Description
A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. The manipulation results in resource consumption. It is possible to launch the attack remotely. The exploit is now public and may be used. The pull request to fix this issue awaits acceptance.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-400
Source
NVD
Vendor
keystonejs
Product
keystone
External References
- https://gist.github.com/nedlir/0431275665076772844ebfe5167e54f6
- https://github.com/keystonejs/keystone/
- https://github.com/keystonejs/keystone/issues/9789
- https://github.com/keystonejs/keystone/pull/9831
- https://vuldb.com/cve/CVE-2026-10802
- https://vuldb.com/submit/831461
- https://vuldb.com/vuln/368251
- https://vuldb.com/vuln/368251/cti
Discussion (0)
Add Comment
No comments yet. Be the first!