Graphql-go Project

Graphql-go

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.13%
  • Veröffentlicht 25.08.2026 17:55:57
  • Zuletzt bearbeitet 09.09.2026 16:03:22

github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in coerceString and coerceBool functions (scalars.go) accept input whose type does not match the declared...

Exploit
  • EPSS 0.87%
  • Veröffentlicht 01.08.2022 22:15:10
  • Zuletzt bearbeitet 25.08.2026 18:17:03

graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.

  • EPSS 1.24%
  • Veröffentlicht 21.01.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:45:16

graphql-go is a GraphQL server with a focus on ease of use. In versions prior to 1.3.0 there exists a DoS vulnerability that is possible due to a bug in the library that would allow an attacker with specifically designed queries to cause stack overfl...