CVE-2023-28867: Graphql-Java

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135.

Affected products

  • Graphql-Java Graphql-Java: before 17.5 (fixed in 17.5); from 18.0, before 18.4 (fixed in 18.4); from 19.0, before 19.4 (fixed in 19.4); version 20.0 only

Published 2023-03-27. Last modified 2026-06-17.