Description
webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, before query validation and complexity controls run. The resulting SIGSEGV can terminate PHP-FPM workers or long-running Swoole, RoadRunner, ReactPHP, or CLI processes and cannot be caught by application-level exception handling. This issue is fixed in version 15.32.3.
Published: 2026-10-08
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service via stack overflow
Action: Immediate Patch
AI Analysis

Impact

Webonyx graphql-php implements the GraphQL specification by performing recursive descent parsing without a recursion limit in several core methods. A malicious GraphQL query that contains deeply nested selection sets, object or list values, or nested list types can force the parser to recurse until the PHP process stack is exhausted. This leads to a SIGSEGV, causing PHP-FPM workers or other long‑running PHP processes to terminate. The failure is not recoverable through application‑level exception handling, resulting in an interruption of service rather than unauthorized code execution.

Affected Systems

The vulnerability affects the PHP library webonyx graphql-php. All releases prior to version 15.32.3 are impacted. Versions 15.32.3 and later include the fix.

Risk and Exploitability

The CVSS score of 8.2 reflects moderate effort and significant impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating it is not currently an actively exploited weakness. The likely attack vector is remote, as an attacker may submit a crafted GraphQL query from any client that can query the GraphQL endpoint. The vulnerability is exploited before query validation and complexity controls run, so it bypasses typical enforcement mechanisms. An attacker can trigger a denial‑of‑service condition by sending sufficiently deep input but cannot achieve code execution or data exfiltration. The attack does not require privileged input or local access; it can be launched over the network to any exposed GraphQL endpoint that uses a vulnerable version of the library.

Generated by OpenCVE AI on October 8, 2026 at 20:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the webonyx graphql-php library to version 15.32.3 or later, which limits recursion depth.
  • If an immediate upgrade is not possible, enforce query depth limits at the application layer (for example, by validating or rejecting requests that exceed a certain nesting level before they reach the parser).
  • Ensure your PHP worker processes (PHP‑FPM, Swoole, RoadRunner, ReactPHP, or CLI) are configured to automatically restart on crash, and monitor logs for unexpected terminations caused by stack overflows.

Generated by OpenCVE AI on October 8, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Webonyx
Webonyx graphql-php
Vendors & Products Webonyx
Webonyx graphql-php

Thu, 08 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, before query validation and complexity controls run. The resulting SIGSEGV can terminate PHP-FPM workers or long-running Swoole, RoadRunner, ReactPHP, or CLI processes and cannot be caught by application-level exception handling. This issue is fixed in version 15.32.3.
Title webonyx graphql-php: Unbounded recursion in parser causes stack overflow on crafted nested input
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Webonyx Graphql-php
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T18:39:56.356Z

Reserved: 2026-10-07T21:07:54.987Z

Link: CVE-2026-107376

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T18:17:22.373

Modified: 2026-10-08T21:34:48.800

Link: CVE-2026-107376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:15:06Z

Weaknesses