CVE-2026-30241 affects Mercurius, a GraphQL adapter for Fastify, prior to version 16.8.0. The vulnerability allows remote clients to bypass queryDepth limits on GraphQL subscription queries over WebSocket connections, potentially leading to denial of service on schemas with recursive types. The CVSS 4.0 score is 2.7 (LOW), indicating a network-based attack with low impact on availability and integrity, but no impact on confidentiality. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules. Community discussion is minimal, with only one mention observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.8.0CPE matchmatch criteria | cpe:2.3:a:mercurius_project:mercurius:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.