A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes.
This issue affects Apache APISIX: 3.17.0.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Thu, 27 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache apisix |
|
| Vendors & Products |
Apache
Apache apisix |
Thu, 27 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue. | |
| Title | Apache APISIX: Unauthenticated CPU-exhaustion DoS | |
| Weaknesses | CWE-407 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-08-27T12:06:27.060Z
Reserved: 2026-08-17T12:56:01.921Z
Link: CVE-2026-75005
Updated: 2026-08-27T10:22:02.818Z
Status : Received
Published: 2026-08-27T10:16:36.493
Modified: 2026-08-27T13:18:37.117
Link: CVE-2026-75005
No data.
OpenCVE Enrichment
Updated: 2026-08-27T10:30:06Z