High severity7.5NVD Advisory· Published Oct 18, 2023· Updated Jun 17, 2026
CVE-2023-42319
CVE-2023-42319
Description
Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/ethereum/go-ethereumGo | <= 1.13.4 | — |
Affected products
3- Geth/go-ethereumdescription
Patches
Vulnerability mechanics
References
5- blog.mevsec.com/posts/geth-dos-with-graphql/nvdExploit
- geth.ethereum.org/docs/fundamentals/securitynvdVendor AdvisoryWEB
- github.com/advisories/GHSA-v9jh-j8px-98vqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-42319ghsaADVISORY
- blog.mevsec.com/posts/geth-dos-with-graphqlghsaWEB
News mentions
0No linked articles in our index yet.