diff --git a/crates/async-graphql/RUSTSEC-0000-0000.md b/crates/async-graphql/RUSTSEC-0000-0000.md new file mode 100644 index 0000000..145c9d0 --- /dev/null +++ b/crates/async-graphql/RUSTSEC-0000-0000.md @@ -0,0 +1,18 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "async-graphql" +date = "2022-07-21" +url = "https://github.com/async-graphql/async-graphql/commit/521769b80039fc8043d1c9883e3d6e5b57359072" +categories = ["denial-of-service"] +cvss = "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" +aliases = ["GHSA-xq3c-8gqm-v648"] +related = ["GHSA-4rx6-g5vg-5f3j"] + +[versions] +patched = [">= 0.15.10"] +``` + +# Denial of service on deeply nested fragment requests + +Deeply nested fragments in a GraphQL request may cause a stack overflow in the server. diff --git a/crates/juniper/RUSTSEC-0000-0000.md b/crates/juniper/RUSTSEC-0000-0000.md new file mode 100644 index 0000000..f4cd70b --- /dev/null +++ b/crates/juniper/RUSTSEC-0000-0000.md @@ -0,0 +1,18 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "juniper" +date = "2022-07-28" +url = "https://github.com/graphql-rust/juniper/security/advisories/GHSA-4rx6-g5vg-5f3j" +categories = ["denial-of-service"] +cvss = "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" +aliases = ["GHSA-4rx6-g5vg-5f3j", "CVE-2022-31173"] +related = ["GHSA-xq3c-8gqm-v648"] + +[versions] +patched = [">= 0.15.10"] +``` + +# Denial of service on deeply nested fragment requests + +Deeply nested fragments in a GraphQL request may cause a stack overflow in the server.