Impact
Any users of Mercurius until version v11.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to /graphql
.
Patches
This was patched in #940.
The patch was released as v11.5.0 and v8.13.2.
Workarounds
Disable subscriptions.
References
Reported publicly as #939.
The same problem was solved in fastify/fastify-websocket#228
Impact
Any users of Mercurius until version v11.5.0 are subjected to a denial of service attack by sending a malformed packet over WebSocket to
/graphql
.Patches
This was patched in #940.
The patch was released as v11.5.0 and v8.13.2.
Workarounds
Disable subscriptions.
References
Reported publicly as #939.
The same problem was solved in fastify/fastify-websocket#228