Back

HIGH

Hasura GraphQL 1.3.3 Denial of Service via Malicious GraphQL Query

Published Dec 22, 2025

Description

Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long query strings and multiple threads to consume server resources and potentially crash the GraphQL endpoint.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Dec 22, 2025
Updated Aug 14, 2026
Reserved Dec 5, 2025
CISA Vulnrichment
Updated Dec 22, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a