QID 995345
Date Published: 2023-09-22
QID 995345: NodeJs (Npm) Security Update for graphql (GHSA-9pv7-vfvm-6vr7)
Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9pv7-vfvm-6vr7 for updates and patch information.
Vendor References
- GHSA-9pv7-vfvm-6vr7 -
github.com/advisories/GHSA-9pv7-vfvm-6vr7
CVEs related to QID 995345
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9pv7-vfvm-6vr7 | graphql |
|