CVE-2025-27407

A flaw was found in graphql-ruby. In affected versions of graphq-ruby, loading a malicious schema definition in the GraphQL::Schema.from_introspection or the GraphQL::Schema::Loader.load can cause rem ...

Continue Reading
CVE-2025-27407

Last updated 13 March...Read More ...

Continue Reading
Gitlab — Vulnerabilities

Gitlab reports: CVE-2025-25291 and CVE-2025-25292 (third party gem ruby-saml) CVE-2025-27407 (third party gem graphql) Denial of Service Due to Inefficient Processing of Untrusted Input Credentials di ...

Continue Reading
graphql allows remote code execution when loading a crafted GraphQL schema

Loading a malicious schema definition in GraphQL::Schema.from_introspection (or GraphQL::Schema::Loader.load) can result in remote code execution. Any system which loads a schema by JSON from an untru ...

Continue Reading
GHSA-Q92J-GRW3-H492 graphql allows remote code execution when loading a crafted GraphQL schema

Summary Loading a malicious schema definition in GraphQL::Schema.from_introspection (or GraphQL::Schema::Loader.load) can result in remote code execution. Any system which loads a schema by JSON from ...

Continue Reading
graphql allows remote code execution when loading a crafted GraphQL schema

Summary Loading a malicious schema definition in GraphQL::Schema.from_introspection (or GraphQL::Schema::Loader.load) can result in remote code execution. Any system which loads a schema by JSON from ...

Continue Reading
CVE-2025-27407 Remote code execution when loading a crafted GraphQL schema

graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition i ...

Continue Reading
CVE-2025-27407

graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition i ...

Continue Reading

Back to Main

Subscribe for the latest news: