CVE-2026-63421CWE-20CWE-480

CVE-2026-63421

High · published August 22, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
38.9
In the wild
Unconfirmed
What it is

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing a remote unauthenticated GraphQL client to provide a negative take value whose magnitude exceeds the configured bound. The bypass also applies to relationship queries and can return more records than the developer intended, potentially exhausting service resources. This issue is fixed in version 6.5.3.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00469 · 38.9th percentile
Weaknesses
CWE-20 · Improper Input Validation; CWE-480 · Use of Incorrect Operator
Published
2026-08-22T01:17Z
References (4)
EPSS history
Timeline
  • 21 AUG 20:15Z
    Keystone: `graphql.maxTake` bypass with negative `take`
    cvelistv5