THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cqmq-8755-7xvh (high) — Keystone vulnerable to `graphql.maxTake` bypass with negative `take`

[GHSA] GHSA-cqmq-8755-7xvh (high) — Keystone vulnerable to `graphql.maxTake` bypass with negative `take`

highgithub_advisoriesPublished 2026-08-21

GHSA-cqmq-8755-7xvh Severity: high CVE: CVE-2026-63421

Keystone vulnerable to `graphql.maxTake` bypass with negative `take`

# Summary The value of `graphql.maxTake` can be bypassed by providing a negative input. This can be used to exceed the developer's intended `graphql.maxTake` value, allowing queries to return results in excess of the `graphql.maxTake` value set.

# Impact This affects any p

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cqmq-8755-7xvh