Inefficient Algorithmic Complexity in Apache APISIX - CVE-2026-75005
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in graphql-limit-count routes when handling a small crafted request. A remote attacker can send a small crafted request to cause a denial of service.
A single request can pin a gateway worker at 100% CPU for an extended period.