PatchSiren

graphql-go project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM graphql-go project CVE published 2026-08-25

CVE-2026-80051

A vulnerability in the GraphQL for Go library through version 0.8.1 allows for a scalar variable value to not match its declared type, potentially leading to a stack overflow condition. This issue arises from the library's failure to validate scalar variable values against their declared types, as mandated by the GraphQL specification. The vulnerability can lead to a stack overflow condition in cases wher [truncated]