Mercurius Project maintains a GraphQL gateway and API composition tool that serves as a request-routing and federation layer, with its vulnerability profile centered on the Mercurius product itself. The durable signal spans web-layer and authorization weaknesses including cross-site request forgery, improper input validation, incorrect authorization logic, and exception-handling gaps that are characteristic of HTTP middleware and API gateway software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mercurius Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-30241HIGH Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDepth limit on GraphQL subscription queries received over WebSoc | Mar 6, 2026 | 8.2 | 26 | NO | NO |
CVE-2021-43801HIGH Mercurius is a GraphQL adapter for Fastify. Any users from [email protected] to 8.11.1 are subjected to a denial of service attack by sending a malformed JSON to `/graphql` unless t | Dec 13, 2021 | 7.5 | 24 | NO | NO |
CVE-2025-64166MEDIUM Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability was identified. The issue arises from incorrect parsing of th | Mar 5, 2026 | 5.4 | 20 | NO | NO |
CVE-2023-22477HIGH Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to | Jan 9, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mercurius Project.
Media articles that mention a CVE ID that affects a product developed by Mercurius Project — matched by CVE ID, not by vendor name.