OSV 1.4.0 · github-reviewed · 修改于 2021-12-14 04:20
发布时间
2021-12-14 05:33
GitHub 审查时间
2021-12-14 04:20
NVD 发布时间
2021-12-14 04:15
源文件
advisories/github-reviewed/2021/12/GHSA-273r-rm8g-7f3x/GHSA-273r-rm8g-7f3x.json
Any users from [email protected] to 8.11.1 are subjected to a denial of service attack by sending a malformed JSON to /graphql unless they are using a custom error handler.
The vulnerability has been fixed in https://github.com/mercurius-js/mercurius/pull/678 and shipped as v8.11.2.
Use a custom error handler.
See https://github.com/mercurius-js/mercurius/issues/677
If you have any questions or comments about this advisory: