HIGH7.5Packagist
GHSA-68jq-c3rv-pcrr· CVE-2026-40476graphql-php is affected by a Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation
Modified: 9/10/2026
package
pkg:packagist/webonyx/graphql-php
graphql-php is affected by a Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation
Modified: 9/10/2026
webonyx/graphql-php has quadratic validation cost in OverlappingFieldsCanBeMerged via inline fragments
Modified: 5/5/2026
webonyx/graphql-php has unbounded recursion in parser that causes stack overflow on crafted nested input
Modified: 5/5/2026