graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule
Unauthenticated quadratic CPU-exhaustion DoS disclosed in graphql-go/graphql up to v0.8.1 via OverlappingFieldsCanBeMergedRule; no fixed version exists.
Evgenios Gkritsis publicly disclosed an algorithmic-complexity denial-of-service flaw in github.com/graphql-go/graphql affecting all released versions up to and including v0.8.1. The defect is triggered via the OverlappingFieldsCanBeMergedRule validation, is unauthenticated and network-reachable, and causes quadratic CPU exhaustion. No fixed version exists; the disclosure was public because the project has no private security-reporting channel or SECURITY.md.
- Unauthenticated, network-reachable quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule
- Affects all graphql-go/graphql releases through v0.8.1; no fix available
- Publicly disclosed because the project lacks a private security reporting channel
Posted by Evgenios Gkritsis on Sep 14 Hello, This reports an algorithmic-complexity denial-of-service defect in github.com/graphql-go/graphql, affecting all released versions up to and including the latest, v0.8.1. No fixed version exists. The project has no private security-reporting channel (GitHub private vulnerability reporting is disabled and there is no SECURITY.md), so this is disclosed publicly. It is unauthenticated, network-reachable, triggered purely by...
This source does not provide full text. Read it at seclists.org.