GraphQL's vulnerability profile centers on a narrowly scoped set of query-language implementations and development tools, including GraphiQL and GraphQL Playground, that serve as interfaces for API interaction and schema exploration. The observed weakness classes reflect the web-facing nature of these tools, concentrating in input-neutralization issues such as cross-site scripting and resource-consumption problems that are characteristic of interactive query processors. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Graphql over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26144MEDIUM Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file w | Sep 20, 2023 | 5.3 | 18 | NO | NO |
CVE-2021-41248MEDIUM GraphiQL is the reference implementation of this monorepo, GraphQL IDE, an official project under the GraphQL Foundation. All versions of graphiql older than [email protected] are vul | Nov 4, 2021 | 4.7 | 18 | NO | NO |
CVE-2021-41249MEDIUM GraphQL Playground is a GraphQL IDE for development of graphQL focused applications. All versions of graphql-playground-react older than [email protected] are vulnera | Nov 4, 2021 | 4.7 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Graphql.
Media articles that mention a CVE ID that affects a product developed by Graphql — matched by CVE ID, not by vendor name.