THREATOPS
THREAT OPSThreat News › Re: graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoS

Re: graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoS

medoss_secPublished 2026-08-29

<p>Posted by William Carrier on Aug 29</p>Follow-up on *CVE-2026-80051*. The CVE record was published with Attack<br /> Vector AV:L. That is incorrect: the correct Attack Vector is AV:N. Nothing<br /> else changes. The transport gating I described is still there, but it<br /> belongs to Attack Requirements, not to Attack Vector.<br /> <br /> There are two consequences of the one root cause (coerce

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/610