Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-40180

22
FAUCET Score

CVE-2023-40180 is a high-severity denial-of-service vulnerability affecting silverstripe-graphql, allowing an unauthenticated attacker to perform a Distributed Denial of Service (DDoS) attack via recursive GraphQL queries, particularly against publicly exposed schemas. With a CVSS score of 7.5, this vulnerability has low attack complexity and can lead to high availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and no known workarounds exist beyond upgrading to patched versions 3.8.2, 4.1.3, 4.2.5, 4.3.4, or 5.0.3.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, < 3.8.2CPE matchmatch criteria
cpe:2.3:a:silverstripe:graphql:*:*:*:*:*:*:*:*
>= 4.0.0, < 4.1.3CPE matchmatch criteria
cpe:2.3:a:silverstripe:graphql:*:*:*:*:*:*:*:*
>= 4.2.0, < 4.2.5CPE matchmatch criteria
cpe:2.3:a:silverstripe:graphql:*:*:*:*:*:*:*:*
>= 4.3.0, < 4.3.4CPE matchmatch criteria
cpe:2.3:a:silverstripe:graphql:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.0.3CPE matchmatch criteria
cpe:2.3:a:silverstripe:graphql:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.90%
Probability of exploitation in next 30 days
EPSS Percentile
56.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0090 is in the 31st percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

composerpatch availablevia ghsa
Product: silverstripe/graphqlFixed in: 3.8.2
composerpatch availablevia ghsa
Product: silverstripe/graphqlFixed in: 4.1.3
composerpatch availablevia ghsa
Product: silverstripe/graphqlFixed in: 4.2.5
composerpatch availablevia ghsa
Product: silverstripe/graphqlFixed in: 4.3.4
composerpatch availablevia ghsa
Product: silverstripe/graphqlFixed in: 5.0.3
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-v23w-pppm-jh66high

Silverstripe GraphQL has DDOS Vulnerability due to lack of protection against recursive queries

Oct 17, 2023

References

docs.silverstripe.org / en/developer_guides/graphql/security_and_best_practices/recursive_or_complex_queries
Mitigation
github.com / silverstripe/silverstripe-graphql/commit/f6d5976ec4608e51184b0db1ee5b9e9a99d2501c
Patch
github.com / silverstripe/silverstripe-graphql/security/advisories/GHSA-v23w-pppm-jh66
Third Party Advisory
github.com / silverstripe/silverstripe-graphql/tree/3.8
Third Party Advisory
silverstripe.org / download/security-releases/CVE-2023-40180
Vendor Advisory