MEDIUM5.3
GHSA-2hmf-46v7-v6fx
gqlparser denial of service vulnerability via the parserDirectives function
Quick fix
GHSA-2hmf-46v7-v6fx — github.com/vektah/gqlparser/v2: upgrade to the fixed version with the command below.
go get github.com/vektah/gqlparser/v2@v2.5.14Details
An issue in vektah gqlparser open-source-library v.2.5.10 allows a remote attacker to cause a denial of service via a crafted script to the parserDirectives function.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/vektah/gqlparser/v2
Introduced in:
0Fixed in: 2.5.14Fix
go get github.com/vektah/gqlparser/v2@v2.5.14Go/github.com/vektah/gqlparser
Introduced in:
0Fixed in: 2.5.14Fix
go get github.com/vektah/gqlparser@v2.5.14References
- https://nvd.nist.gov/vuln/detail/CVE-2023-49559[ADVISORY]
- https://github.com/99designs/gqlgen/issues/3118[WEB]
- https://github.com/vektah/gqlparser/commit/36a3658873bf5a107f42488dfc392949cdd02977[WEB]
- https://gist.github.com/uvzz/d3ed9d4532be16ec1040a2cf3dfec8d1[WEB]
- https://github.com/advisories/GHSA-2hmf-46v7-v6fx[ADVISORY]
- https://github.com/vektah/gqlparser[PACKAGE]
- https://github.com/vektah/gqlparser/blob/master/parser/query.go#L316[WEB]