PT-2026-106267 · Unknown · Graphql-Tools

·

CVE-2026-104852

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GraphQL Tools versions prior to 12.0.1
Description The mergeDeep() function in the GraphQL Tools utils package fails to exclude proto, constructor, or prototype keys while recursively merging source objects. An unauthenticated client can alias fields to these names, causing responses from two subgraphs to collide during supergraph result merging. This allows the function to traverse Object and Function prototypes and overwrite Function.prototype.call with a value supplied by a subgraph, resulting in a denial of service that breaks all subsequent requests until the process is restarted.
Recommendations Update to version 12.0.1.

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104852
GHSA-7MX3-VVMW-HJMV

Affected Products

Graphql-Tools