Hasura develops a GraphQL API engine that mediates between applications and data sources, presenting an attack surface centered on query processing and data-access control. Vulnerabilities affecting this product skew toward serious outcomes and recur through weakness classes including resource exhaustion, path traversal, command and SQL injection, and authorization flaws that reflect the engine's position as a database gateway and API translation layer. Defenders should treat this vendor's security advisories as high-priority for any exposed GraphQL endpoints; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hasura over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-47748CRITICAL Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject c | Jan 21, 2026 | 9.8 | 32 | NO | NO |
CVE-2022-46792HIGH Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, | Dec 8, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-47713HIGH Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. A | Dec 22, 2025 | 7.5 | 24 | NO | NO |
CVE-2023-27588HIGH Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL Engine prior to versions 1.3.4, | Mar 14, 2023 | 7.5 | 24 | NO | NO |
CVE-2019-1020015HIGH graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT. | Jul 29, 2019 | 7.5 | 24 | NO | NO |
CVE-2021-47714MEDIUM Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg | Dec 22, 2025 | 5.5 | 20 | NO | NO |
CVE-2021-47715MEDIUM Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attac | Dec 22, 2025 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hasura.
Media articles that mention a CVE ID that affects a product developed by Hasura — matched by CVE ID, not by vendor name.