The webonyx/graphql-php package has an unbounded recursion vulnerability in its parser, which causes a stack overflow on crafted nested input. This results in a SIGSEGV in the PHP runtime, killing the FPM/CLI worker process. The vulnerability affects PHP applications using the webonyx/graphql-php package, especially those with untrusted input or GraphQL APIs. Defenders should prioritize verifying exposure [truncated]
A vulnerability in graphql-go, a Go implementation of GraphQL, allows for excessive CPU usage during validation of queries with thousands of repeated identical fields. This issue, fixed in version 15.31.5, affects graphql-php and has a CVSS score of 6.9. The vulnerability is caused by the OverlappingFieldsCanBeMerged validation rule performing O(n²) pairwise comparisons, allowing an attacker to cause exce [truncated]