Graphql
10 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Graphql, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Graphql CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 2 |
| 2026-09 | 0 |
Severity
How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High2
- Medium3
Latest CVEs
The 10 most recently published vulnerabilities affecting Graphql.
- CVE-2026-19869Privilege Escalation via Dropped Field-Level @authentication—
- CVE-2026-5423Subscription Authentication Bypass via Unverified connectionParams.jwt—
- GHSA-3h96-34p3-xm76GraphQL-Ruby's Ruby lexer does not count comment tokens for the purposes of max_query_string_tokens—
- CVE-2026-24125Path Traversal in @tinacms/graphql6.3
- CVE-2021-47748Hasura GraphQL 1.3.3 - Remote Code Execution9.8
- CVE-2025-27407Remote code execution when loading a crafted GraphQL schema9.0
- CVE-2023-44401Silverstripe GraqhQL's view permissions are bypassed for paginated lists of ORM data5.3
- CVE-2023-40180Denial of service vulnerability in silverstripe-graphql via recursive queries7.5
- CVE-2023-26144Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large...5.3
- CVE-2023-28104silverstripe/graphql Denial of Service vulnerability7.5
Product grouping is registry-driven, with AI assist and human review. How it works