VYPR
Vendor

Graphql Hive

Products
6
CVEs
4
Across products
6
Status
Private

Products

6

Recent CVEs

4
  • CVE-2026-23735HigJan 16, 2026
    risk 0.50cvss epss 0.01

    GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extendable modules out of your GraphQL server. From 2.2.1 to before 2.4.1 and 3.1.1, when 2 or more parallel requests are made which trigger the same service, the…

  • CVE-2021-41248HigNov 4, 2021
    risk 0.39cvss 7.1epss 0.01

    GraphiQL is the reference implementation of this monorepo, GraphQL IDE, an official project under the GraphQL Foundation. All versions of graphiql older than [email protected] are vulnerable to compromised HTTP schema introspection responses or schema prop values with malicious…

  • CVE-2021-41249HigNov 4, 2021
    risk 0.39cvss 7.1epss 0.01

    GraphQL Playground is a GraphQL IDE for development of graphQL focused applications. All versions of graphql-playground-react older than [email protected] are vulnerable to compromised HTTP schema introspection responses or schema prop values with malicious GraphQL…

  • CVE-2023-26144MedSep 20, 2023
    risk 0.28cvss 5.3epss 0.01

    Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system…