PT-2024-13747 · Unknown · Vektah Gqlparser

Yuval Moravchick

·

Published

2024-06-12

·

Updated

2025-06-18

·

CVE-2023-49559

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions vektah gqlparser version 2.5.10
Description An issue in the vektah gqlparser open-source-library allows a remote attacker to cause a denial of service via a crafted script to the parserDirectives function. This issue can be exploited to overload the parser, resulting in a denial of service.
Recommendations For version 2.5.10, consider disabling the parserDirectives function as a temporary workaround until a patch is available. Restrict access to the parseDirectives function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2023-49559
GHSA-2HMF-46V7-V6FX
GO-2024-2920

Affected Products

Vektah Gqlparser