GHSA-5gc2-7c65-8fq8
async-graphql Directive Overload
Details
### Impact
- Service Disruption: The server may become unresponsive or extremely slow, potentially leading to downtime. - Resource Exhaustion: Excessive use of server resources, such as CPU and memory, could negatively impact other services running on the same infrastructure. - User Experience Degradation: Users may experience delays or failures when accessing the service, which could lead to frustration and loss of trust in the service.
### Patches
1. Upgrade to v7.0.10 2. Use [SchemaBuilder.limit_directives](https://docs.rs/async-graphql/latest/async_graphql/struct.SchemaBuilder.html#method.limit_directives) to limit the maximum number of directives for a single field.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 7.0.10Upgrade async-graphql to 7.0.10 or newer (ecosystem crates.io).
References
- https://github.com/async-graphql/async-graphql/security/advisories/GHSA-5gc2-7c65-8fq8[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-47614[ADVISORY]
- https://github.com/async-graphql/async-graphql/commit/7f1791488463d4e9c5adcd543962173e2f6cbd34[WEB]
- https://github.com/async-graphql/async-graphql[PACKAGE]