VDB
GO-2024-2920
GO-2024-2920
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Denial of service vulnerability via the parseDirectives function in github.com/vektah/gqlparser
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| wolfi | dagger | 0, 0, 0 |
| wolfi | zot | 0, 0, 0 |
| chainguard | melange | 0, 0, 0 |
| wolfi | guac | 0, 0, 0 |
| chainguard | zot | 0, 0 |
| chainguard | dagger | 0, 0 |
| github.com | vektah/gqlparser/v2 | 0, 0 |
| github.com | vektah/gqlparser | 0, 0 |
| chainguard | guac | 0, 0 |
| wolfi | melange | 0, 0, 0 |
Timeline
- Jul 1, 2024 CVE Published
- Feb 4, 2026 CVE Updated
References
- https://github.com/advisories/GHSA-2hmf-46v7-v6fx advisory
- https://github.com/vektah/gqlparser/blob/master/parser/query.go#L316 url
- https://github.com/99designs/gqlgen/issues/3118 discussion
- https://github.com/vektah/gqlparser/commit/36a3658873bf5a107f42488dfc392949cdd02977 fix
- https://gist.github.com/uvzz/d3ed9d4532be16ec1040a2cf3dfec8d1 exploit