Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0446 | Mercurius is a GraphQL adapter for Fastify. Any users of Mercurius until version 10.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to `/graphql`. This issue was patched in #940. As a workaround, users can disable subscriptions. |
Github GHSA |
GHSA-cm8h-q92v-xcfc | mercurius has Uncaught Exception when using subscriptions |
Mon, 10 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:31:05.984Z
Reserved: 2022-12-29T17:41:28.087Z
Link: CVE-2023-22477
Updated: 2024-08-02T10:13:48.466Z
Status : Modified
Published: 2023-01-09T15:15:11.127
Modified: 2024-11-21T07:44:53.093
Link: CVE-2023-22477
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA