GraphQL Java is a narrowly scoped Java library implementation of the GraphQL query language, deployed as a dependency in applications that require GraphQL API support. The observed vulnerability exposure is modest and concentrates in the core library itself; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Graphql Java Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37734HIGH graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, | Sep 12, 2022 | 7.5 | 26 | NO | NO |
CVE-2023-28867HIGH In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0 | Mar 27, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Graphql Java Project.
Media articles that mention a CVE ID that affects a product developed by Graphql Java Project — matched by CVE ID, not by vendor name.