graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes CPU resources. The fixed versions are 19.0 and later, 18.3, and 17.4, and 0.0.0-2022-07-26T05-45-04-226aabd9.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Graphql-java | Graphql-java_project | * | 17.4 (excluding) |
Graphql-java | Graphql-java_project | 18.0 (including) | 18.3 (excluding) |
Red Hat build of Eclipse Vert.x 4.3.3 | RedHat | graphql-java | * |
Red Hat build of Quarkus 2.13.5 | RedHat | * | |
RHINT Service Registry 2.3.0 GA | RedHat | graphql-java | * |