CVE-2023-26144
Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance.
**Note:** It was not proven that this vulnerability can crash the process.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.45%
- Percentil entre todas las CVEs puntuadas: 73
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Prueba de concepto en GitHub (no verificada) · Lista de pruebas de concepto en GitHub
⚠️ Las pruebas de concepto de GitHub no están verificadas: algunas son falsas o contienen malware. No las ejecute nunca fuera de un laboratorio aislado.
Tecnologías afectadas (1)
CWE
- CWE-400
- CWE-400
Referencias
- https://github.com/graphql/graphql-js/commit/f94b511386c7e47bd0380dcd56553dc063320226
- https://github.com/graphql/graphql-js/issues/3955
- https://github.com/graphql/graphql-js/pull/3972
- https://github.com/graphql/graphql-js/releases/tag/v16.8.1
- https://security.snyk.io/vuln/SNYK-JS-GRAPHQL-5905181
- https://github.com/graphql/graphql-js/commit/f94b511386c7e47bd0380dcd56553dc063320226
- https://github.com/graphql/graphql-js/issues/3955
- https://github.com/graphql/graphql-js/pull/3972
- https://github.com/graphql/graphql-js/releases/tag/v16.8.1
- https://security.snyk.io/vuln/SNYK-JS-GRAPHQL-5905181
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-26144",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-26144",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-09-24T20:32:04.245711Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "report@snyk.io",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "report@snyk.io",
"affectedData": [
{
"vendor": "n/a",
"product": "graphql",
"versions": [
{
"status": "affected",
"version": "16.3.0",
"lessThan": "16.8.1",
"versionType": "semver"
}
]
}
]
}
],
"published": "2023-09-20T05:15:39.923",
"references": [
{
"url": "https://github.com/graphql/graphql-js/commit/f94b511386c7e47bd0380dcd56553dc063320226",
"tags": [
"Patch"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/graphql/graphql-js/issues/3955",
"tags": [
"Exploit",
"Issue Tracking",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/graphql/graphql-js/pull/3972",
"tags": [
"Product"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/graphql/graphql-js/releases/tag/v16.8.1",
"tags": [
"Release Notes"
],
"source": "report@snyk.io"
},
{
"url": "https://security.snyk.io/vuln/SNYK-JS-GRAPHQL-5905181",
"tags": [
"Exploit",
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/graphql/graphql-js/commit/f94b511386c7e47bd0380dcd56553dc063320226",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/graphql/graphql-js/issues/3955",
"tags": [
"Exploit",
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/graphql/graphql-js/pull/3972",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/graphql/graphql-js/releases/tag/v16.8.1",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.snyk.io/vuln/SNYK-JS-GRAPHQL-5905181",
"tags": [
"Exploit",
"Issue Tracking",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "report@snyk.io",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance.\r\r**Note:** It was not proven that this vulnerability can crash the process."
},
{
"lang": "es",
"value": "Las versiones del paquete graphql desde 16.3.0 y anteriores a 16.8.1 son vulnerables a la Denegación de Servicio (DoS) debido a comprobaciones insuficientes en el archivo OverlappingFieldsCanBeMergedRule.ts al analizar consultas grandes. Esta vulnerabilidad permite a un atacante degradar el rendimiento del sistema. **Nota:** No se ha demostrado que esta vulnerabilidad pueda bloquear el proceso."
}
],
"lastModified": "2026-06-17T05:42:46.593",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:graphql:graphql:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "F350F09D-E2EC-454B-AE86-D1685AFDD9D2",
"versionEndExcluding": "16.8.1",
"versionStartIncluding": "16.3.0"
},
{
"criteria": "cpe:2.3:a:graphql:graphql:17.0.0:alpha1:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "37819AB7-A406-4FC1-BB34-C949848AF13E"
},
{
"criteria": "cpe:2.3:a:graphql:graphql:17.0.0:alpha2:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "17EC77C2-6B00-4742-A98E-08874B982117"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "report@snyk.io"
}