CVE-2021-47748
- EPSS 0.53%
- Veröffentlicht 21.01.2026 17:27:31
- Zuletzt bearbeitet 02.02.2026 18:11:25
Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL querie...
CVE-2021-47714
- EPSS 0.02%
- Veröffentlicht 22.12.2025 21:35:25
- Zuletzt bearbeitet 27.12.2025 17:15:40
Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to ...
CVE-2021-47715
- EPSS 0.05%
- Veröffentlicht 22.12.2025 21:35:25
- Zuletzt bearbeitet 26.12.2025 16:57:55
Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit the vulnerability by sending crafted POST requests to...
CVE-2021-47713
- EPSS 0.07%
- Veröffentlicht 22.12.2025 21:35:24
- Zuletzt bearbeitet 26.12.2025 16:56:27
Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long query strings ...
CVE-2023-27588
- EPSS 0.53%
- Veröffentlicht 14.03.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:53:12
Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL Engine prior to versions 1.3.4, 2.55.1, 2.20.1, and 2.21.0-beta1. Projects running on Hasura Cloud wer...
CVE-2022-46792
- EPSS 0.54%
- Veröffentlicht 08.12.2022 06:15:08
- Zuletzt bearbeitet 23.04.2025 15:15:58
Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)
CVE-2019-1020015
- EPSS 0.24%
- Veröffentlicht 29.07.2019 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:11
graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT.