THREATOPS
THREAT OPSThreat News › graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule

graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule

lowoss_secPublished 2026-09-14

<p>Posted by Evgenios Gkritsis on Sep 14</p>Hello,<br /> <br /> This reports an algorithmic-complexity denial-of-service defect in<br /> github.com/graphql-go/graphql, affecting all released versions up to and<br /> including the latest, v0.8.1. No fixed version exists. The project has no<br /> private security-reporting channel (GitHub private vulnerability reporting<br /> is disabled and there i

Original source: https://seclists.org/oss-sec/2026/q3/776