EEF-CVE-2026-67585
Atom Exhaustion via _entities Representation Keys in DivvyPayHQ absinthe_federation
Quick fix
EEF-CVE-2026-67585 — absinthe_federation: upgrade to the fixed version with the command below.
mix deps.update absinthe_federation Details
## Summary
Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe\_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted \_entities representation keys.
Every key of every object in the representations argument of the federation-mandated \_entities field is converted with String.to\_atom/1 by convert\_key/2 in lib/absinthe/federation/schema/entities\_field.ex. representations is typed as the open-ended \_Any scalar, so its keys bypass schema coercion and the attacker names them freely. Atoms are never garbage collected and the BEAM atom table is hard-capped (about 1,048,576 entries by default), so one request carrying tens of thousands of unique keys creates that many permanent atoms and a handful of such requests exhausts the table and aborts the node. The impact is confined to availability: no data is read or altered, and recovery requires restarting the application.
This issue affects absinthe\_federation: from 0.1.0 before 0.9.3.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.1.0 Fixed in: 0.9.3 mix deps.update absinthe_federation References
- https://github.com/DivvyPayHQ/absinthe_federation/security/advisories/GHSA-55hv-mwvr-phf3 [ADVISORY]
- https://cna.erlef.org/cves/CVE-2026-67585.html [WEB]
- https://github.com/DivvyPayHQ/absinthe_federation/commit/c3838cda2a7f65c4893291668c223b0d6acf4516 [FIX]
- https://hex.pm/packages/absinthe_federation [PACKAGE]