Components
Vulnerabilities
Pricing
MCP
API
Docs
Sign up
Login
graphql 16.4.0 | Vulnerabilities | Sonatype Guide
npm
graphql
16.4.0
graphql 16.4.0
Published
Apr 25, 2022
•
Policy
compliance
npm Registry
Developer Trust Score
N/A
Recommended Version:
x.y.z
Latest version with 0 known vulnerabilities that meets your policy.
Compare Versions
Overview
Overview
Versions
289
Versions
289
Vulnerabilities
1
Vulnerabilities
1
Dependencies
0
Dependencies
0
Severity
Critical
(0)
High
(0)
Medium
(1)
Low
(0)
CVSS Score
0.0
10.0
EPSS Score
0.0
1.0
Malware
KEV Status
Published
Filter
Sort: Published (Newest first)
5.3
CVE-2023-26144
Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this vulnerability can crash the process.
affected
Severity
Medium
Published
Sep 21, 2023