PT-2026-23759 · Mercurius · Mercurius

Tinkanet

·

Publicado

2026-03-06

·

Atualizado

2026-03-12

·

CVE-2026-30241

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Mercurius versions prior to 16.8.0
Description Mercurius does not properly enforce the configured queryDepth limit on GraphQL subscription queries received over WebSocket connections. The depth check functions as expected for HTTP queries and mutations, but subscription queries bypass this validation. This allows a remote client to send excessively nested subscription queries via WebSocket, circumventing the intended depth restriction. In schemas containing recursive types, this can result in a denial of service due to exponential data resolution with each subscription event.
Recommendations Update to version 16.8.0 or later. Disable subscriptions and queries over WebSocket.

Exploit

Correção

DoS

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-30241
GHSA-M4H2-MJFM-MP55

Produtos afetados

Mercurius