Vulnerability CVE-2022-30288


Published: 2022-05-04   Modified: 2022-05-05

Description:
Agoo through 2.14.2 does not reject GraphQL fragment spreads that form cycles, leading to an application crash.

 References:
https://github.com/ohler55/agoo/issues/109
https://spec.graphql.org/October2021/#sec-Fragment-spreads-must-not-form-cycles
https://github.com/nicholasaleks/graphql-threat-matrix/blob/master/implementations/agoo.md

Copyright 2026, cxsecurity.com

 

Back to Top