Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to `/graphql`. This issue was patched in #940. As a workaround, users can disable subscriptions.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-01-09T14:12:24.837Z
Updated: 2024-08-02T10:13:48.466Z
Reserved: 2022-12-29T17:41:28.087Z
Link: CVE-2023-22477
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-01-09T15:15:11.127
Modified: 2023-11-07T04:06:59.093
Link: CVE-2023-22477
Redhat
No data.