GHSA-g56x-7j6w-g8r8
Dashboard / Vulnerabilities / GHSA-g56x-7j6w-g8r8
Summary: Grackle has StackOverflowError in GraphQL query processing
Details: ### Impact Prior to this fix, the GraphQL query parsing was vulnerable to `StackOverflowError`s. The possibility of small queries resulting in stack overflow is a potential denial of service vulnerability. This potentially affects all applications using Grackle which have untrusted users. > [!CAUTION] > **No specific knowledge of an application's GraphQL schema would be required to construct a pathological query.** ### Patches The stack overflow issues have been resolved in the v0.18.0 release of Grackle. ### Workarounds Users could interpose a sanitizing layer in between untrusted input and Grackle query processing.
References: https://github.com/typelevel/grackle/security/advisories/GHSA-g56x-7j6w-g8r8, https://nvd.nist.gov/vuln/detail/CVE-2023-50730, https://github.com/typelevel/grackle/commit/56e244b91659cf385df590fc6c46695b6f36cbfd, https://github.com/typelevel/grackle, https://github.com/typelevel/grackle/releases/tag/v0.18.0
Affected packages
Package
Name: org.typelevel:grackle-core_2.13
Purl: pkg:maven/org.typelevel/grackle-core_2.13
Affected ranges
Type: ECOSYSTEM
Events:
