GHSA-9pv7-vfvm-6vr7

Suggest an improvement
Source
https://github.com/advisories/GHSA-9pv7-vfvm-6vr7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-9pv7-vfvm-6vr7/GHSA-9pv7-vfvm-6vr7.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9pv7-vfvm-6vr7
Aliases
Published
2023-09-20T06:30:50Z
Modified
2023-11-01T05:01:30.496378Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
graphql Uncontrolled Resource Consumption vulnerability
Details

Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance.

Note: It was not proven that this vulnerability can crash the process.

Database specific
{
    "nvd_published_at": "2023-09-20T05:15:39Z",
    "cwe_ids": [
        "CWE-400"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-09-21T17:03:11Z"
}
References

Affected packages

npm / graphql

Package

Affected ranges

Type
SEMVER
Events
Introduced
16.3.0
Fixed
16.8.1