Malicious inputs can cause a panic.
A maliciously crafted input can cause a stack overflow and panic. Any user with access to the GraphQL can send such a query.
This issue only occurs when using the graphql.MaxDepth schema option (which is highly recommended in most cases).
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0300" }