Unauthenticated attackers can exhaust server resources (CPU/memory/stack) by sending specially crafted GraphQL queries — e.g. deeply nested inline fragments — to the GraphQL endpoint, causing denial of service. Adobe APSB26-49.
This vulnerability affects the following application versions:
- Magento 2.4.7
- Magento 2.4.7-beta1
- Magento 2.4.7-beta2
- Magento 2.4.7-beta3
- Magento 2.4.7-p1
- Magento 2.4.7-p2
- Magento 2.4.7-p3
- Magento 2.4.7-p4
- Magento 2.4.7-p5
- Magento 2.4.7-p6
- Magento 2.4.7-p7
- Magento 2.4.7-p8
- Magento 2.4.7-p9
- Magento 2.4.8
- Magento 2.4.8-beta1
- Magento 2.4.8-beta2
- Magento 2.4.8-p1
- Magento 2.4.8-p2
- Magento 2.4.8-p3
- Magento 2.4.8-p4
- Magento 2.4.9-alpha1
- Magento 2.4.9-alpha2
- Magento 2.4.9-alpha3
- Magento 2.4.9-beta1
SOCIAL SHARE CARD GENERATOR