VDB
Sign up
MEDIUM5.3

GHSA-3h96-34p3-xm76

GraphQL-Ruby's Ruby lexer does not count comment tokens for the purposes of max_query_string_tokens

Quick fix

GHSA-3h96-34p3-xm76 — graphql: upgrade to the fixed version with the command below.

bundle update graphql

Details

GraphQL-Ruby's `max_query_string_tokens` configuration didn't count comment tokens against the limit, allowing strings to be processed even after the configured maximum had actually been reached.

In patched versions, the Ruby lexer does count these tokens.

GraphQL-CParser is not affected by this problem.

`max_query_string_tokens` was introduced in v2.3.1. Each 2.x version has received a new patch release for including a fix.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/graphql
Introduced in: 2.6.0Fixed in: 2.6.1
Fixbundle update graphql
RubyGems/graphql
Introduced in: 2.5.0Fixed in: 2.5.26
Fixbundle update graphql
RubyGems/graphql
Introduced in: 2.4.0Fixed in: 2.4.18
Fixbundle update graphql
RubyGems/graphql
Introduced in: 2.3.1Fixed in: 2.3.23
Fixbundle update graphql

References