CVE-2026-81633 - Unhandled KeyError in AshGraphql relay node resolution crashes queries via an unknown type segment
Brief
CVE ID : CVE-2026-81633
Published : Aug. 30, 2026, 6:22 p. m.
- 53 minutes ago
Description : Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id: ...) query with an unhandled KeyError.
AshGraphql. Graphql. Resolver. resolve_node/2 decodes the client-supplied global ID with decode_relay_id/1, which only base64-decodes the string and splits it on : without validating the type segment. The decoded type is passed straight to Map. fetch! (type_to_domain_and_resource_map, type). Because fetch!
raises on a missing key, a relay ID whose type segment is a valid atom that is not a relay-exposed type aborts the resolver before its resolve/2 clauses and their rescue handlers run, so the error never becomes a GraphQL error and may expose a stacktrace. Common resource names are easy to guess. The fix uses Map.
