Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @graphql-tools/utils
  4. ›
  5. CVE-2026-104852

CVE-2026-104852: GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`

October 5, 2026

Closed by https://github.com/ardatan/graphql-tools/pull/8423 Mitigated in Hive Gateway by https://github.com/graphql-hive/gateway/pull/2600

A client can alias fields to constructor, __proto__ or prototype so that the response keys from two subgraphs collide on those names during result merging. Because mergeDeep recursed through inherited properties, the merge walked {}.constructor to Object, then Object.__proto__ to Function.prototype, and wrote a subgraph-supplied value over Function.prototype.call, breaking every subsequent request in the process until restart. This is remotely triggerable by an unauthenticated client with a single query against any supergraph that merges an object from two subgraphs, which is the ordinary @shareable or entity case, so it is a denial of service rather than a theoretical hardening issue.

{
shared {
fieldA
constructor: fieldB {
__proto__: child {
call: value
}
}
}
}

References

  • github.com/advisories/GHSA-7mx3-vvmw-hjmv
  • github.com/ardatan/graphql-tools/commit/0b9529f1988fd36186a7c106a6efe0356f1b7f2e
  • github.com/ardatan/graphql-tools/pull/8423
  • github.com/ardatan/graphql-tools/releases/tag/@graphql-tools/utils@12.0.1
  • github.com/ardatan/graphql-tools/security/advisories/GHSA-7mx3-vvmw-hjmv
  • github.com/graphql-hive/gateway/pull/2600
  • nvd.nist.gov/vuln/detail/CVE-2026-104852

Code Behaviors & Features

Detect and mitigate CVE-2026-104852 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 12.0.1

Fixed versions

  • 12.0.1

Solution

Upgrade to version 12.0.1 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Source file

npm/@graphql-tools/utils/CVE-2026-104852.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 06 Oct 2026 00:16:36 +0000.