spring-graphql is vulnerable to Denial of Service (DoS)
75
High Risk
spring-graphql forwards client-supplied Spring Data pagination arguments to the repository. A crafted Connection query can exhaust memory or overload the datastore. Auto-registered QueryByExampleDataFetcher or QuerydslDataFetcher Connection fields without complexity limits are the affected pattern. The patch bounds pagination arguments before they reach the repository.
You are affected if you are using a version that falls within the vulnerable range and a Connection query field is auto-registered from a Spring Data repository without extra query-complexity limits.
spring-graphql is vulnerable to Denial of Service (DoS) in versions 1.2.0 - 2.0.4.
Upgrade the org.springframework.graphql:spring-graphql library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant