<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T12:39:16.099207+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-324639</id>
    <title>EUVD-2026-324639</title>
    <updated>2026-10-06T12:39:16.104478+00:00</updated>
    <content>EUVD-2026-324639</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-324639"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47707</id>
    <title>fkie_cve-2026-47707</title>
    <updated>2026-10-06T12:39:16.104530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not consider how many times a fragments internal aliases are expanded during execution. this allows an attacker to bypass alias limits and force the server to resolve and render a significantly higher number of aliases than allowed, potentially leading to a  dos via resource exhaustion. Version 0.315.7 contains a fix for the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47707"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fr49-mhgj-crfc</id>
    <title>GHSA-fr49-mhgj-crfc — Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification</title>
    <updated>2026-10-06T12:39:16.104583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: strawberry-graphql</p>
<p>### Summary
The MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not consider how many times a fragments internal aliases are expanded during execution. this allows an attacker to bypass alias limits and force the server to resolve and render a significantly higher number of aliases than allowed, potentially leading to a  dos via resource exhaustion.</p>
<p>### Details
The current implementation of alias counting in strawberry/extensions/max_aliases.py uses a static approach
```
for selection in selection_set_owner.selection_set.selections: 
    if isinstance(selection, FieldNode) and selection.alias:
        result += 1</p>
<p>if isinstance(selection, (FieldNode, InlineFragmentNode)) and ~~~:
        result += count_fields_with_alias(selection)
```</p>
<p>When a FragmentSpread is used multiple times, the actual number of aliases processed by the execution engine is</p>
<p>**Total Aliases = query aliases + (num of spreads * aliases within fragment)**</p>
<p>Because Strawberry only performs a static sum of the text, it misses this multiplication</p>
<p>### PoC
**server code**
```
import strawberry
from fastapi import FastAPI
from strawberry.fastapi import GraphQLRouter
from strawberry.extensions import MaxAliasesLimiter</p>
<p>@strawberry.type
class User:
    name: str = "GONA"</p>
<p>@strawberry.type
class Query:
    @strawberry.field
    def user(self) -&gt; User:
        return Us…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fr49-mhgj-crfc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2284</id>
    <title>PYSEC-2026-2284</title>
    <updated>2026-10-06T12:39:16.104663+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: strawberry-graphql</p>
<p>Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not consider how many times a fragments internal aliases are expanded during execution. this allows an attacker to bypass alias limits and force the server to resolve and render a significantly higher number of aliases than allowed, potentially leading to a  dos via resource exhaustion. Version 0.315.7 contains a fix for the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2284"/>
  </entry>
</feed>
