CVE-2022-31173

HIGH

Juniper <0.15.10 - Use After Free

Title source: llm
STIX 2.1

Description

Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resulting in a program crash. This issue has been addressed in version 0.15.10. Users are advised to upgrade. Users unable to upgrade should limit the recursion depth manually.

Scores

CVSS v3 7.5
EPSS 0.0062
EPSS Percentile 70.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-674 CWE-400
Status published
Products (2)
crates.io/juniper 0 - 0.15.10crates.io
juniper_project/juniper < 0.15.10
Published Aug 01, 2022
Tracked Since Feb 18, 2026