HIGHVulnerability

CVE-2026-76763

A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An unauthenticated remote attacker can exploit this by sending a GraphQL query containing a large exponent float literal. This can lead to the allocation of extremely large BigInteger objects, causing CPU exhaustion or an OutOfMemoryError, resulting in a denial of service.

Properties

severity
HIGH
score
7.5
epss_score
0.00354
cve_id
CVE-2026-76763
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-31T14:17:23.050
last_modified
2026-09-01T21:03:04.987
epss_percentile
0.2849

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Validation of Specified Quantity in Input

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76763 — Ninja Signal Threat Intelligence | Ninja Signal