High severity7.5NVD Advisory· Published Jul 29, 2019· Updated Jun 17, 2026
CVE-2019-1020015
CVE-2019-1020015
Description
graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:hasura:graphql_engine:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:hasura:graphql_engine:*:*:*:*:*:*:*:*range: <1.0.0
- cpe:2.3:a:hasura:graphql_engine:1.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:hasura:graphql_engine:1.0.0:beta.1:*:*:*:*:*:*
- cpe:2.3:a:hasura:graphql_engine:1.0.0:beta.2:*:*:*:*:*:*
- (no CPE)range: <1.0.0-beta.3
- graphql-engine/graphql-enginev5Range: < 1.0.0-beta.3
Patches
Vulnerability mechanics
References
1- github.com/hasura/graphql-engine/commit/f2f14e727b051e3003ba44b9b63eab8186b291acnvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.