Impact
Webonyx graphql-php implements the GraphQL specification by performing recursive descent parsing without a recursion limit in several core methods. A malicious GraphQL query that contains deeply nested selection sets, object or list values, or nested list types can force the parser to recurse until the PHP process stack is exhausted. This leads to a SIGSEGV, causing PHP-FPM workers or other long‑running PHP processes to terminate. The failure is not recoverable through application‑level exception handling, resulting in an interruption of service rather than unauthorized code execution.
Affected Systems
The vulnerability affects the PHP library webonyx graphql-php. All releases prior to version 15.32.3 are impacted. Versions 15.32.3 and later include the fix.
Risk and Exploitability
The CVSS score of 8.2 reflects moderate effort and significant impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating it is not currently an actively exploited weakness. The likely attack vector is remote, as an attacker may submit a crafted GraphQL query from any client that can query the GraphQL endpoint. The vulnerability is exploited before query validation and complexity controls run, so it bypasses typical enforcement mechanisms. An attacker can trigger a denial‑of‑service condition by sending sufficiently deep input but cannot achieve code execution or data exfiltration. The attack does not require privileged input or local access; it can be launched over the network to any exposed GraphQL endpoint that uses a vulnerable version of the library.
OpenCVE Enrichment