Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fr49-mhgj-crfc | Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification |
Fri, 05 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Strawberry strawberry Graphql
|
|
| CPEs | cpe:2.3:a:strawberry:strawberry_graphql:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Strawberry strawberry Graphql
|
Fri, 05 Jun 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Strawberry
Strawberry strawberry |
|
| Vendors & Products |
Strawberry
Strawberry strawberry |
Thu, 04 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not consider how many times a fragments internal aliases are expanded during execution. this allows an attacker to bypass alias limits and force the server to resolve and render a significantly higher number of aliases than allowed, potentially leading to a dos via resource exhaustion. Version 0.315.7 contains a fix for the issue. | |
| Title | Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-04T15:06:13.934Z
Reserved: 2026-05-19T21:29:25.481Z
Link: CVE-2026-47707
Updated: 2026-06-04T15:05:42.549Z
Status : Analyzed
Published: 2026-06-04T15:16:55.283
Modified: 2026-06-05T17:38:44.720
Link: CVE-2026-47707
No data.
OpenCVE Enrichment
Updated: 2026-06-05T07:45:35Z
Github GHSA