graphql-core is vulnerable to Denial of Service (DoS)
75
High Risk
The OverlappingFieldsCanBeMerged validation rule compares selected fields to detect merge conflicts before any resolver runs. On documents with many nested inline fragments the number of comparisons grows quadratically, so a small query drives the rule into extreme running time. Untrusted queries can therefore exhaust CPU during validation and deny service without authentication. The fix enforces a per-document comparison budget that aborts validation with an error once the limit is exceeded.
You are affected if you run a version that falls within the vulnerable range and your application validates GraphQL queries from untrusted input.
graphql-core is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 3.2.11.
Upgrade the graphql-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.