cve/2024/CVE-2024-40094.md
2025-09-29 16:08:36 +00:00

669 B

CVE-2024-40094

Description

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

POC

Reference

No PoCs from references.

Github