Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Uncaught Exception in mercurius
Vulnerability Description
Mercurius is a GraphQL adapter for Fastify. Any users from Mercurius@8.10.0 to 8.11.1 are subjected to a denial of service attack by sending a malformed JSON to `/graphql` unless they are using a custom error handler. The vulnerability has been fixed in https://github.com/mercurius-js/mercurius/pull/678 and shipped as v8.11.2. As a workaround users may use a custom error handler.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
对因果或异常条件的不恰当检查
Vulnerability Title
Mercurius 代码问题漏洞
Vulnerability Description
Mercurius是GraphQL适配器Fastify 。 Mercurius 8.10.0至8.11.1存在代码问题漏洞,攻击者可以通过该漏洞造成拒绝服务攻击。
CVSS Information
N/A
Vulnerability Type
N/A