logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-26144

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-26144

Description:
Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this vulnerability can crash the process.
Last updated date:
09/22/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
09/22/2023
Reference url to background

https://github.com/graphql/graphql-js/issues/3955

Type:
exploit
Confidence:
HIGH
Date of publishing:
09/22/2023
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy