Vulnerability GHSA-7mx3-vvmw-hjmv

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 hours ago
October 05, 2026 at 10:56 PM UTC
GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`
5.0.1-alpha-00e0ef2.0 - 12.0.1-rc-20260907155438-70f93ec122ac510059d67d2c95fa983767d228e4
5.0.1-alpha-00e0ef2.0 - 12.0.1-rc-20260907155438-70f93ec122ac510059d67d2c95fa983767d228e4

Summary

GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`

Details

Closed by https://github.com/ardatan/graphql-tools/pull/8423 Mitigated in Hive Gateway by https://github.com/graphql-hive/gateway/pull/2600

A client can alias fields to constructor, __proto__ or prototype so that the response keys from two subgraphs collide on those names during result merging. Because mergeDeep recursed through inherited properties, the merge walked {}.constructor to Object, then Object.__proto__ to Function.prototype, and wrote a subgraph-supplied value over Function.prototype.call, breaking every subsequent request in the process until restart. This is remotely triggerable by an unauthenticated client with a single query against any supergraph that merges an object from two subgraphs, which is the ordinary @shareable or entity case, so it is a denial of service rather than a theoretical hardening issue.

{
  shared {
    fieldA
    constructor: fieldB {
      __proto__: child {
        call: value
      }
    }
  }
}

Impacted packages

Timeline

Published
8 hours ago
October 05, 2026 at 10:56 PM UTC
Fixed (12.0.1)
28 days ago
September 07, 2026 at 04:06 PM UTC
Last Modified
8 hours ago
October 05, 2026 at 11:15 PM UTC