CVE-2026-47706
EUVD-2026-3426904.06.2026, 15:16
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detection in fragment spreads. When a query contains circular fragment references the determine_depth function enters an infinite recursion, leading to a RecursionError and crashing the validation process. Version 0.315.7 patches the issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| strawberry | strawberry_graphql | 0.71.0 ≤ 𝑥 < 0.315.7 |
𝑥
= Vulnerable software versions