HIGH7.5
GHSA-v62j-cxhh-fq22
graphql-java vulnerable to Denial of Service via GraphQL query that consumes CPU resources
Quick fix
GHSA-v62j-cxhh-fq22 — com.graphql-java:graphql-java: upgrade to the fixed version with the command below.
# pom.xml: bump <version>17.4</version> for com.graphql-java:graphql-javaDetails
graphql-java before 19.0, 18.3, and 17.4 is vulnerable to Denial of Service. An attacker send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0, 18.3, and 17.4.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/com.graphql-java:graphql-java
Introduced in:
0Fixed in: 17.4Fix
# pom.xml: bump <version>17.4</version> for com.graphql-java:graphql-javaMaven/com.graphql-java:graphql-java
Introduced in:
18.0Fixed in: 18.3Fix
# pom.xml: bump <version>18.3</version> for com.graphql-java:graphql-javaReferences
- https://nvd.nist.gov/vuln/detail/CVE-2022-37734[ADVISORY]
- https://github.com/graphql-java/graphql-java/issues/2888[WEB]
- https://github.com/graphql-java/graphql-java/pull/2892[WEB]
- https://github.com/graphql-java/graphql-java[PACKAGE]
- https://github.com/graphql-java/graphql-java/discussions/2958[WEB]
- https://github.com/graphql-java/graphql-java/releases[WEB]
- https://security.snyk.io/vuln/SNYK-JAVA-COMGRAPHQLJAVA-3021519[WEB]