CVE-2026-107376 — webonyx graphql-php is a PHP implementation of the GraphQL specification.
Description
webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, before query validation and complexity controls run. The resulting SIGSEGV can terminate PHP-FPM workers or long-running Swoole, RoadRunner, ReactPHP, or CLI processes and cannot be caught by application-level exception handling. This issue is fixed in version 15.32.3.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:HHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
None
Confidentiality
I
Low
Integrity
A
High
Availability
References
- advisory[email protected]https://github.com/webonyx/graphql-php/commit/6c1d6009a0f7557f66753bcfd07badd15acf77f4
- advisory[email protected]https://github.com/webonyx/graphql-php/commit/7b7f2080ca5f7d5340a696fc5701b19a9222d2c2
- advisory[email protected]https://github.com/webonyx/graphql-php/releases/tag/v15.32.3
- advisory134c704f-9b21-4f2e-91b3-4a467353bcc0https://github.com/webonyx/graphql-php/security/advisories/GHSA-r7cg-qjjm-xhqq
Related threats
same CWE or vendorCVE-2026-19498 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to cause a denial…
CVE-2026-19498 · 2h ago
Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion
OSV · 6h ago
Coraza JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash)
OSV · 6h ago
CVE-2026-107300 — msgpack5 is a msgpack v5 implementation for node.js and the browser.
CVE-2026-107300 · 7h ago
CVE-2026-107298 — msgpack5 is a msgpack v5 implementation for node.js and the browser.
CVE-2026-107298 · 7h ago
CVE-2026-107678 — FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in av_encryption_init_info_free() in libavutil/encryption_info.c, which recursively …
CVE-2026-107678 · 8h ago