Jan. 9, 2023, 3:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to `/graphql`. This issue was patched in #940. As a workaround, users can disable subscriptions.

attack cve denial of service denial of service attack graphql issue malformed packet service subscriptions version websocket workaround

Cyber Software Engineering, Senior Advisor

@ Peraton | Annapolis Junction, MD, United States

Cybersecurity Architect, Lead (NJUS)

@ NetJets | Columbus, OH, US, 43219

Security Operations Analyst

@ Commonwealth Financial Network | Waltham, MA, United States

Penetration Tester – Senior Associate - Cybersecurity

@ JPMorgan Chase & Co. | Buenos Aires, Argentina

Manager - Endpoint Security

@ Novo Nordisk | Bengaluru, Karnataka, IN

Senior Officer, Identity Access Management Administrator, Group Information Security (Contract)

@ UOB | Singapore (City Area), SG, 048624