Database/Container, Kubernetes & orchestration
RHACS Central: unbounded GraphQL query depth lets an authenticated user stall the management plane
Impact
Central does not bound the depth of GraphQL queries on its authenticated API, so a holder of any valid API token can send deeply nested queries that consume enough CPU and memory to take Central out of service. The scope is marked changed because Central is the management plane for cluster security: while it is down, admission control decisions, policy evaluation and violation reporting for every attached cluster stop being observable. On a GPU fleet that runs tenant workloads under RHACS policy, this is a way for a low-privileged token to blind the control that is supposed to be watching those workloads, without touching a single node. Availability only; no data disclosure or policy modification is described. Affects RHACS 4.9 through 4.11.
Who can reach it
Network access to Central's API with any valid RHACS API token. Authentication is required but no elevated role is described, so a token issued for read-only integration work is sufficient.
What to do
Upgrade RHACS to the version in the applicable erratum (RHSA-2026:36207, RHSA-2026:36319 or RHSA-2026:36625 depending on the 4.9, 4.10 or 4.11 stream) and roll the Central deployment. That is a restart of Central and its supporting pods, not a change on the secured clusters, so sensors keep enforcing while Central restarts. Meanwhile, narrow network exposure of the Central API and audit outstanding API tokens.
References
Related entries
- KubeVirt: Symlink path traversal in the virt-exportserver VMExport directory endpointCVE-2026-9804 · KubeVirtHigh
- ingress-nginx: Custom nginx snippets in an Ingress annotation retrieve the ingress-nginx service-account tokenCVE-2021-25742 · ingress-nginxHigh
- ingress-nginx: Ingress `path` can be pointed at the service-account token fileCVE-2021-25745 · ingress-nginxHigh
- ingress-nginx: Directive injection through Ingress annotations obtains controller credentialsCVE-2021-25746 · ingress-nginxHigh
- ingress-nginx: Newline character bypasses `path` sanitizationCVE-2021-25748 · ingress-nginxHigh
- Istio: Localhost access to the istiod pod lets a user impersonate any workload identity in the meshCVE-2022-39388 · IstioHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.