{
  "threat_severity" : "Important",
  "public_date" : "2026-07-06T08:38:30Z",
  "bugzilla" : {
    "description" : "stackrox: stackrox: Unbounded GraphQL query depth allows authenticated denial of service",
    "id" : "2480505",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2480505"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.7",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-400",
  "details" : [ "A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.", "A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane." ],
  "statement" : "Red Hat Product Security is aware of this issue affecting RHACS Central. This flaw allows an authenticated user to reduce availability of the Central management component. Red Hat is not aware of malicious exploitation of this issue outside of coordinated testing. Updates addressing this issue will be released according to the RHACS support lifecycle. Refer to the associated errata when available for affected versions and update instructions.",
  "acknowledgement" : "This issue was discovered by Moritz Clasmeier (Red Hat).",
  "affected_release" : [ {
    "product_name" : "Red Hat Advanced Cluster Security 4.9",
    "release_date" : "2026-07-07T00:00:00Z",
    "advisory" : "RHSA-2026:36319",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.9::el8",
    "package" : "advanced-cluster-security/rhacs-main-rhel8:1783357116"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security for Kubernetes 4.10",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36625",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.10::el8",
    "package" : "advanced-cluster-security/rhacs-main-rhel8:1783357140"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security for Kubernetes 4.11",
    "release_date" : "2026-07-07T00:00:00Z",
    "advisory" : "RHSA-2026:36207",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.11::el9",
    "package" : "advanced-cluster-security/rhacs-main-rhel9:1783352589"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-9165\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-9165" ],
  "name" : "CVE-2026-9165",
  "mitigation" : {
    "value" : "There is no complete mitigation other than installing the update once\navailable.",
    "lang" : "en:us"
  },
  "csaw" : false
}