nicholasaleks/graphql-threat-matrix

nicholasaleks/graphql-threat-matrix

Releases0
Stars361
GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

Agoo before 2.14.3 does not reject GraphQL fragment spreads that form cycles, leading to an application crash. NOTE: the vendor has disputed this on the grounds that it is not the server's responsibility to "enforce all the various ways a developer could write code with logic errors.