@escape.tech/graphql-armor-cost-limit is vulnerable to Unlimited Resource Consumption
65
Medium Risk
Affected versions of this package are vulnerable to allocation of resources without proper limits or throttling. The computeComplexity function performs insufficient validation when the ignoreIntrospection option—enabled by default—is used. This allows an attacker to bypass query cost restrictions by naming a query or fragment using __schema, potentially leading to resource exhaustion.
You are affected if you are using a version that falls within the vulnerable range.
@escape.tech/graphql-armor-cost-limit is vulnerable to Unlimited Resource Consumption in versions 1.0.0 - 2.4.1.
Upgrade the @escape.tech/graphql-armor-cost-limit library to the patch version or set the ignoreIntrospection option to false.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant