EEF-CVE-2026-67585
Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
Quick fix
EEF-CVE-2026-67585 — absinthe_federation: upgrade to the fixed version with the command below.
mix deps.update absinthe_federationDetails
## Summary
Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted `_entities` representation keys.
Every key of every object in the `representations` argument of the federation-mandated `_entities` field is converted with `String.to_atom/1` by `convert_key/2` in `lib/absinthe/federation/schema/entities_field.ex`. `representations` is typed as the open-ended `_Any` scalar, so its keys bypass schema coercion and the attacker names them freely. Atoms are never garbage collected and the BEAM atom table is hard-capped (about 1,048,576 entries by default), so one request carrying tens of thousands of unique keys creates that many permanent atoms and a handful of such requests exhausts the table and aborts the node. The impact is confined to availability: no data is read or altered, and recovery requires restarting the application.
This issue affects absinthe_federation: from 0.1.0 before 0.9.3.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/DivvyPayHQ/absinthe_federation/security/advisories/GHSA-55hv-mwvr-phf3[ADVISORY]
- https://cna.erlef.org/cves/CVE-2026-67585.html[WEB]
- https://github.com/DivvyPayHQ/absinthe_federation/commit/c3838cda2a7f65c4893291668c223b0d6acf4516[FIX]
- https://hex.pm/packages/absinthe_federation[PACKAGE]