Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-31173

23
FAUCET Score

CVE-2022-31173 impacts the Juniper GraphQL server library for Rust, allowing for uncontrolled recursion that can lead to a program crash. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely with low attack complexity, resulting in a denial of service. While no active exploitation, public exploit code, or significant community discussion has been observed, users are advised to upgrade to version 0.15.10 or implement manual recursion depth limits.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.15.10CPE matchmatch criteria
cpe:2.3:a:juniper_project:juniper:*:*:*:*:*:rust:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.33%
Probability of exploitation in next 30 days
EPSS Percentile
68.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0133 is in the 48th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
rustpatch availablevia ghsa
Product: juniperFixed in: 0.15.10

Vendor Advisories (1)

rustGHSA-4rx6-g5vg-5f3jhigh

Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow

Jul 29, 2022

References

github.com / graphql-rust/juniper/blob/juniper-v0.15.10/juniper/CHANGELOG.md
Release NotesThird Party Advisory
github.com / graphql-rust/juniper/commit/2b609ee057be950e3454b69fadc431d120e407bb
PatchThird Party Advisory
github.com / graphql-rust/juniper/commit/8d28cdba6eb10f53490ba41d1b5cb40506c2de22
PatchThird Party Advisory
github.com / graphql-rust/juniper/security/advisories/GHSA-4rx6-g5vg-5f3j
ExploitThird Party Advisory