THREAT OPS › Threat News › Re: graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoS
Re: graphql-go/graphql <= 0.8.1: improper scalar input-type validation -> type confusion and unrecoverable stack-overflow DoS
<p>Posted by William Carrier on Aug 29</p>Follow-up on *CVE-2026-80051*. The CVE record was published with Attack<br /> Vector AV:L. That is incorrect: the correct Attack Vector is AV:N. Nothing<br /> else changes. The transport gating I described is still there, but it<br /> belongs to Attack Requirements, not to Attack Vector.<br /> <br /> There are two consequences of the one root cause (coerce
Indicators of compromise
- CVE-2026-80051cve
Original source: https://seclists.org/oss-sec/2026/q3/610