THREAT OPS › Threat News › graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoS
graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoS
<p>Posted by First name Last name on Aug 25</p>Hello,<br /> <br /> This reports a security defect in github.com/graphql-go/graphql (GraphQL<br /> for Go), affecting all released versions up to and including the latest,<br /> v0.8.1 (released 2023-04-10). No fixed version exists.<br /> <br /> The repository has no private security-reporting channel: GitHub private<br /> vulnerability reporting is d
Original source: https://seclists.org/oss-sec/2026/q3/570