Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
5.9
CVE-2026-80051
- EPSS 0.13%
- Veröffentlicht 25.08.2026 17:55:57
- Zuletzt bearbeitet 09.09.2026 16:03:22
github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in coerceString and coerceBool functions (scalars.go) accept input whose type does not match the declared...
7.5
CVE-2022-37315
- EPSS 0.87%
- Veröffentlicht 01.08.2022 22:15:10
- Zuletzt bearbeitet 25.08.2026 18:17:03
graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.
6.5
CVE-2022-21708
- EPSS 1.24%
- Veröffentlicht 21.01.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:16
graphql-go is a GraphQL server with a focus on ease of use. In versions prior to 1.3.0 there exists a DoS vulnerability that is possible due to a bug in the library that would allow an attacker with specifically designed queries to cause stack overfl...
1