Description
A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. The manipulation results in resource consumption. It is possible to launch the attack remotely. The exploit is now public and may be used. The pull request to fix this issue awaits acceptance.
Problem types
Product status
Timeline
| 2026-06-04: | Advisory disclosed |
| 2026-06-04: | VulDB entry created |
| 2026-06-04: | VulDB entry last update |
Credits
nedlir (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/368251 (VDB-368251 | keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption)
vuldb.com/vuln/368251/cti (VDB-368251 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-10802 (CVE-2026-10802 | CVE Analysis and Report)
vuldb.com/submit/831461 (Submit #831461 | Keystone KeystoneJS 2026-03-19 Denial of Service)
github.com/keystonejs/keystone/issues/9789
github.com/keystonejs/keystone/pull/9831
gist.github.com/nedlir/0431275665076772844ebfe5167e54f6
github.com/keystonejs/keystone/