VDB
Sign up
HIGH7.5

GHSA-5gc2-7c65-8fq8

async-graphql Directive Overload

Details

### Impact

- Service Disruption: The server may become unresponsive or extremely slow, potentially leading to downtime. - Resource Exhaustion: Excessive use of server resources, such as CPU and memory, could negatively impact other services running on the same infrastructure. - User Experience Degradation: Users may experience delays or failures when accessing the service, which could lead to frustration and loss of trust in the service.

### Patches

1. Upgrade to v7.0.10 2. Use [SchemaBuilder.limit_directives](https://docs.rs/async-graphql/latest/async_graphql/struct.SchemaBuilder.html#method.limit_directives) to limit the maximum number of directives for a single field.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/async-graphql
Introduced in: 0Fixed in: 7.0.10

Upgrade async-graphql to 7.0.10 or newer (ecosystem crates.io).

References