Mercurius Project
Mercurius Project Mercurius: vulnerabilities and CVEs
Mercurius Project Mercurius has 4 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months2
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30241 | Low (2.7) | 0.46% | — | Mar 6, 2026 | Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDepth limit on GraphQL subscription queries received over WebSocket connections. The depth check is… |
| CVE-2025-64166 | Medium (5.4) | 0.17% | — | Mar 5, 2026 | Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability was identified. The issue arises from incorrect parsing of the Content-Type header in requests.… |
| CVE-2023-22477 | High (7.5) | 1.1% | — | Jan 9, 2023 | Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to `/graphql`. This issue was patched in… |
| CVE-2021-43801 | High (7.5) | 1.5% | — | Dec 13, 2021 | Mercurius is a GraphQL adapter for Fastify. Any users from Mercurius@8.10.0 to 8.11.1 are subjected to a denial of service attack by sending a malformed JSON to `/graphql` unless they are using a custom error handler.… |