Strawberry GraphQL 是一个用于创建 GraphQL API 的库。在版本 0.312.3 到 0.327.2 之间, 中的遗留 graphql-ws 订阅处理器在操作自然完成后,不会将其从 和 中移除。如果配置了 (每连接最大订阅数),持久 WebSocket 连接上的客户端可以通过为一次性订阅使用不同的操作 ID,即使这些订阅已发送完成,也会占满连接配置的最大订阅槽位,导致后续该连接上的合法操作因“达到订阅上限”而被拒绝。现代 graphql-transport-ws 协议以及未配置每连接上限的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| strawberry-graphql | strawberry | >= 0.312.3, < 0.327.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet