High severity7.5OSV Advisory· Published Dec 22, 2025· Updated Jun 17, 2026
CVE-2021-47713
CVE-2021-47713
Description
Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long query strings and multiple threads to consume server resources and potentially crash the GraphQL endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3v1.0.0-alpha0, v1.0.0-alpha01, v1.0.0-alpha02, …+ 2 more
- (no CPE)range: v1.0.0-alpha0, v1.0.0-alpha01, v1.0.0-alpha02, …
- cpe:2.3:a:hasura:graphql_engine:1.3.3:*:*:*:*:*:*:*
- (no CPE)range: <1.3.3
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/49789nvdExploit
- www.vulncheck.com/advisories/hasura-graphql-denial-of-service-via-malicious-graphql-querynvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.