CVE-2024-47614: Async-Graphql

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead to Service Disruption, Resource Exhaustion, and User Experience Degradation. This vulnerability is fixed in 7.0.10.

Affected products

  • Async-Graphql Async-Graphql: before 7.0.10 (fixed in 7.0.10)
  • Graphql Async-Graphql: before 7.0.10 (fixed in 7.0.10)

Published 2024-10-03. Last modified 2026-06-17.