CVE-2023-26144
graphql Uncontrolled Resource Consumption vulnerability
5.3
MEDIUM
CVSS 3.1
EPSS 2.1%
Description
Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this vulnerability can crash the process.
How to fix CVE-2023-26144
To remediate CVE-2023-26144, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 16.8.1 or later
Is CVE-2023-26144 being exploited?
Low — EPSS is 2.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0
- >= 16.3.0, < 16.8.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |