VDB
Sign up
HIGH7.5

GHSA-v62j-cxhh-fq22

graphql-java vulnerable to Denial of Service via GraphQL query that consumes CPU resources

Quick fix

GHSA-v62j-cxhh-fq22 — com.graphql-java:graphql-java: upgrade to the fixed version with the command below.

# pom.xml: bump <version>17.4</version> for com.graphql-java:graphql-java

Details

graphql-java before 19.0, 18.3, and 17.4 is vulnerable to Denial of Service. An attacker send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0, 18.3, and 17.4.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.graphql-java:graphql-java
Introduced in: 0Fixed in: 17.4
Fix# pom.xml: bump <version>17.4</version> for com.graphql-java:graphql-java
Maven/com.graphql-java:graphql-java
Introduced in: 18.0Fixed in: 18.3
Fix# pom.xml: bump <version>18.3</version> for com.graphql-java:graphql-java

References