GO-2022-0300
Dashboard / Vulnerabilities / GO-2022-0300
GO-2022-0300
Published: 15 Jul 2022Last Modified: 20 May 2024
Aliases:
Summary: Panic via malicious inputs in github.com/graph-gophers/graphql-go
Details: Malicious inputs can cause a panic. A maliciously crafted input can cause a stack overflow and panic. Any user with access to the GraphQL can send such a query. This issue only occurs when using the graphql.MaxDepth schema option (which is highly recommended in most cases).
References: https://github.com/graph-gophers/graphql-go/commit/eae31ca73eb3473c544710955d1dbebc22605bfe
Affected packages
Package
Name: github.com/graph-gophers/graphql-go
Purl: pkg:golang/github.com/graph-gophers/graphql-go
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -1.3.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
