nicholasaleks

1 exploit Active since May 2022
CVE-2022-30288 WRITEUP HIGH WRITEUP
ohler/agoo < 2.14.3 - Denial of Service via Cyclic GraphQL Fragment Spreads
Agoo before 2.14.3 does not reject GraphQL fragment spreads that form cycles, leading to an application crash. NOTE: the vendor has disputed this on the grounds that it is not the server's responsibility to "enforce all the various ways a developer could write code with logic errors.
CVSS 7.5