ZeroHour
oss-securitypublished ()ingested

graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule

mediumVulnerabilityimportance 32
AI summary · glm-5.3

Unauthenticated quadratic CPU-exhaustion DoS disclosed in graphql-go/graphql up to v0.8.1 via OverlappingFieldsCanBeMergedRule; no fixed version exists.

Evgenios Gkritsis publicly disclosed an algorithmic-complexity denial-of-service flaw in github.com/graphql-go/graphql affecting all released versions up to and including v0.8.1. The defect is triggered via the OverlappingFieldsCanBeMergedRule validation, is unauthenticated and network-reachable, and causes quadratic CPU exhaustion. No fixed version exists; the disclosure was public because the project has no private security-reporting channel or SECURITY.md.

  • Unauthenticated, network-reachable quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule
  • Affects all graphql-go/graphql releases through v0.8.1; no fix available
  • Publicly disclosed because the project lacks a private security reporting channel
Full article

Posted by Evgenios Gkritsis on Sep 14 Hello, This reports an algorithmic-complexity denial-of-service defect in github.com/graphql-go/graphql, affecting all released versions up to and including the latest, v0.8.1. No fixed version exists. The project has no private security-reporting channel (GitHub private vulnerability reporting is disabled and there is no SECURITY.md), so this is disclosed publicly. It is unauthenticated, network-reachable, triggered purely by...

This source does not provide full text. Read it at seclists.org.