Known Vulnerabilities for Graphql-php by Webonyx
Listed below are 10 of the newest known vulnerabilities associated with "Graphql-php" by "Webonyx".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40476 json | graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule... | Not Provided | 2026-04-17 | 2026-04-17 |
| CVE-2026-40324 json | Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recu... | Not Provided | 2026-04-18 | 2026-04-17 |
| CVE-2026-40173 json | Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclo... | Not Provided | 2026-04-15 | 2026-04-16 |
| CVE-2026-35577 json | Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.0, th... | Not Provided | 2026-04-09 | 2026-04-13 |
| CVE-2026-35526 json | Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription hand... | Not Provided | 2026-04-07 | 2026-04-08 |
| CVE-2026-35523 json | Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentica... | Not Provided | 2026-04-07 | 2026-04-09 |
| CVE-2026-35441 json | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoint... | Not Provided | 2026-04-06 | 2026-04-06 |
| CVE-2026-35413 json | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION... | Not Provided | 2026-04-06 | 2026-04-06 |
| CVE-2026-35401 json | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can includ... | Not Provided | 2026-04-08 | 2026-04-08 |
| CVE-2026-34976 json | Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the ... | Not Provided | 2026-04-06 | 2026-04-07 |