« Volver al listado

CVE-2026-47706

Estado: AnalizadaMedia (5.3)—

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detection in fragment spreads. When a query contains circular fragment references the determine_depth function enters an infinite recursion, leading to a RecursionError and crashing the validation process. Version 0.315.7 patches the issue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-47706",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-47706",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-04T15:38:17.270610Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "strawberry-graphql",
          "product": "strawberry",
          "versions": [
            {
              "status": "affected",
              "version": ">= 0.71.0, < 0.315.7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-04T15:16:54.763",
  "references": [
    {
      "url": "https://github.com/strawberry-graphql/strawberry/releases/tag/0.315.7",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/strawberry-graphql/strawberry/security/advisories/GHSA-qfwv-87qj-98xq",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/strawberry-graphql/strawberry/security/advisories/GHSA-qfwv-87qj-98xq",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        },
        {
          "lang": "en",
          "value": "CWE-674"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detection in fragment spreads. When a query contains circular fragment references the determine_depth function enters an infinite recursion, leading to a RecursionError and crashing the validation process. Version 0.315.7 patches the issue."
    },
    {
      "lang": "es",
      "value": "Strawberry GraphQL es una biblioteca para crear APIs de GraphQL. En las versiones 0.71.0 a la 0.315.6, la extensión QueryDepthLimiter es vulnerable a un DoS a nivel de aplicación debido a la falta de detección de ciclos en las propagaciones de fragmentos. Cuando una consulta contiene referencias circulares de fragmentos, la función determine_depth entra en una recursión infinita, lo que lleva a un RecursionError y bloquea el proceso de validación. La versión 0.315.7 corrige el problema."
    }
  ],
  "lastModified": "2026-07-22T20:10:00.127",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:strawberry:strawberry_graphql:*:*:*:*:*:python:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F93E1FF4-BCEE-4EB2-9F5C-772AE8A8C7E5",
              "versionEndExcluding": "0.315.7",
              "versionStartIncluding": "0.71.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}