PT-2026-106267 · Unknown · Graphql-Tools
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GraphQL Tools versions prior to 12.0.1
Description
The
mergeDeep() function in the GraphQL Tools utils package fails to exclude proto, constructor, or prototype keys while recursively merging source objects. An unauthenticated client can alias fields to these names, causing responses from two subgraphs to collide during supergraph result merging. This allows the function to traverse Object and Function prototypes and overwrite Function.prototype.call with a value supplied by a subgraph, resulting in a denial of service that breaks all subsequent requests until the process is restarted.Recommendations
Update to version 12.0.1.
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Graphql-Tools