Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-75005 is an Inefficient Algorithmic Complexity vulnerability (CWE-407) affecting Apache APISIX versions up to 3.17.0, where a single small HTTP request to graphql-limit-count routes can consume 100% of a gateway worker's CPU for an extended period. This denial-of-service condition is particularly dangerous because it requires minimal attacker effort—a tiny payload—to disable critical API gateway infrastructure. Organizations running APISIX as an API management layer are directly affected, as attackers can systematically exhaust all worker processes and render the gateway unavailable to legitimate traffic. The simplicity of exploitation makes this a high-risk vulnerability for any deployment using graphql-limit-count rate limiting rules.
While CVE-2026-75005 does not map to specific MITRE ATT&CK techniques in its current classification, Casky.ai's threat detection would identify the attack pattern through Resource Exhaustion and Denial of Service analysis using Claude's extended reasoning capabilities. Practitioners leveraging Casky would observe findings related to computational resource depletion, anomalous CPU utilization spikes on gateway workers, and the correlation between minimal request volume and maximum resource consumption. The platform's 754 mapped security skills would flag algorithmic complexity weaknesses in rate-limiting implementations, helping teams identify whether their APISIX deployments contain vulnerable graphql-limit-count routes before exploitation occurs. Immediate detection focuses on traffic pattern anomalies: legitimate GraphQL requests should consume proportional resources, but a single crafted request causing sustained 100% CPU indicates the algorithmic flaw requiring urgent patching to version 3.18.0.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-75005. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation