Description
In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135.
References (5)
Core 5
Core References
Issue Tracking, Patch
https://github.com/graphql-java/graphql-java/pull/3112
Scores
CVSS v3
7.5
EPSS
0.0105
EPSS Percentile
59.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (3)
com.graphql-java/graphql-java
0 - 0.0.0-2023-03-20T01-49-44-80e3135Maven
graphql-java/graphql-java
20.0
graphql-java/graphql-java
< 17.5
Published
Mar 27, 2023
Tracked Since
Feb 18, 2026