CVE-2021-47713

Source
https://cve.org/CVERecord?id=CVE-2021-47713
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47713.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-47713
Published
2025-12-22T22:15:58.720Z
Modified
2026-03-15T22:01:28.447550Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long query strings and multiple threads to consume server resources and potentially crash the GraphQL endpoint.

References

Affected packages

Git / github.com/hasura/graphql-engine

Affected ranges

Type
GIT
Repo
https://github.com/hasura/graphql-engine
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.3"
        }
    ]
}

Affected versions

v1.*
v1.0.0
v1.0.0-alpha0
v1.0.0-alpha01
v1.0.0-alpha02
v1.0.0-alpha03
v1.0.0-alpha04
v1.0.0-alpha05
v1.0.0-alpha06
v1.0.0-alpha07
v1.0.0-alpha08
v1.0.0-alpha09
v1.0.0-alpha10
v1.0.0-alpha11
v1.0.0-alpha12
v1.0.0-alpha13
v1.0.0-alpha14
v1.0.0-alpha15
v1.0.0-alpha16
v1.0.0-alpha17
v1.0.0-alpha18
v1.0.0-alpha20
v1.0.0-alpha21
v1.0.0-alpha22
v1.0.0-alpha23
v1.0.0-alpha24
v1.0.0-alpha25
v1.0.0-alpha26
v1.0.0-alpha27
v1.0.0-alpha28
v1.0.0-alpha29
v1.0.0-alpha30
v1.0.0-alpha31
v1.0.0-alpha32
v1.0.0-alpha33
v1.0.0-alpha34
v1.0.0-alpha35
v1.0.0-alpha36
v1.0.0-alpha37
v1.0.0-alpha38
v1.0.0-alpha39
v1.0.0-alpha40
v1.0.0-alpha41
v1.0.0-alpha42
v1.0.0-alpha43
v1.0.0-alpha44
v1.0.0-alpha45
v1.0.0-beta.1
v1.0.0-beta.10
v1.0.0-beta.2
v1.0.0-beta.3
v1.0.0-beta.4
v1.0.0-beta.5
v1.0.0-beta.6
v1.0.0-beta.7
v1.0.0-beta.8
v1.0.0-beta.9
v1.0.0-rc.1
v1.3.1
v1.3.1-beta.1
v1.3.2
v1.3.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-47713.json"