CVE-2021-43801: Improper Check for Unusual or Exceptional Conditions
(updated )
Mercurius is a GraphQL adapter for Fastify. It is vulnerable to a denial of service attack by sending a malformed JSON to /graphql
unless they are using a custom error handler. As a workaround users may use a custom error handler.
References
Detect and mitigate CVE-2021-43801 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →