CVE-2023-26144
Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries.
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this vulnerability can crash the process.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- graphql/graphql
- Source
- report@snyk.io
References
- https://github.com/graphql/graphql-js/commit/f94b511386c7e47bd0380dcd56553dc063320226Patch
- https://github.com/graphql/graphql-js/issues/3955Exploit, Issue Tracking, Third Party Advisory
- https://github.com/graphql/graphql-js/pull/3972Product
- https://github.com/graphql/graphql-js/releases/tag/v16.8.1Release Notes
- https://security.snyk.io/vuln/SNYK-JS-GRAPHQL-5905181Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/graphql/graphql-js/commit/f94b511386c7e47bd0380dcd56553dc063320226Patch
- https://github.com/graphql/graphql-js/issues/3955Exploit, Issue Tracking, Third Party Advisory
- https://github.com/graphql/graphql-js/pull/3972Product
- https://github.com/graphql/graphql-js/releases/tag/v16.8.1Release Notes
- https://security.snyk.io/vuln/SNYK-JS-GRAPHQL-5905181Exploit, Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.