GraphQL Java is a reference implementation library for building GraphQL servers in Java, occupying a narrow but foundational role in the GraphQL ecosystem where it serves as a building block for downstream applications. The vulnerability footprint reflects the library's parsing and query-execution responsibilities; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Graphql Java over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37734HIGH graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, | Sep 12, 2022 | 7.5 | 26 | NO | NO |
CVE-2023-28867HIGH In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0 | Mar 27, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Graphql Java.
Media articles that mention a CVE ID that affects a product developed by Graphql Java — matched by CVE ID, not by vendor name.