Graphql-go Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-80051

    github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in coerceString and coerceBool functions (scalars.go) accept input whose type does not match the declared String, ID, or Boolean scalar instead of raising the request error that the GraphQL specification mandates. In some cases (but not any typical case of JSON sent to a website), a deeply nested value leads to an unrecoverable "fatal error: stack overflow" condition.

    Last Modified: Aug 25, 2026
    Published: Aug 25, 2026

    CVE-2022-37315

    graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.

    Last Modified: Aug 25, 2026
    Published: Aug 01, 2022

    CVE-2022-21708

    Denial of Service in graphql-go

    Last Modified: Apr 23, 2025
    Published: Jan 21, 2022
    Items Per Page
    Graphql-Go_Project Vulnerabilities & Security CVEs | CVE-DB