CVE-2026-67585 | DivvyPayHQ absinthe_federation up to 0.9.2 entities_field.ex String.to_atom representations allocation of resources (EUVD-2026-54531)

SecurityVulns

A vulnerability has been found in DivvyPayHQ absinthe_federation up to 0.9.2 and classified as problematic. Affected by this issue is the function String.to_atom of the file lib/absinthe/federation/schema/entities_field.ex. The manipulation of the argument representations leads to allocation of resources.

This vulnerability is uniquely identified as CVE-2026-67585. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More