CVE-2022-46792: Hasura Graphql Engine

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)

Affected products

  • Hasura Graphql Engine: from 2.10.0, before 2.10.2 (fixed in 2.10.2); from 2.11.0, before 2.11.3 (fixed in 2.11.3); from 2.13.0, before 2.13.2 (fixed in 2.13.2); from 2.15.0, before 2.15.2 (fixed in 2.15.2); version 2.12.0 only; version 2.14.0 only

Published 2022-12-08. Last modified 2026-06-17.