GHSA-7mx3-vvmw-hjmvHigh

GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`

Published
October 5, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Closed by https://github.com/ardatan/graphql-tools/pull/8423 Mitigated in Hive Gateway by https://github.com/graphql-hive/gateway/pull/2600

A client can alias fields to constructor, __proto__ or prototype so that the response keys from two subgraphs collide on those names during result merging. Because mergeDeep recursed through inherited properties, the merge walked {}.constructor to Object, then Object.__proto__ to Function.prototype, and wrote a subgraph-supplied value over Function.prototype.call, breaking every subsequent request in the process until restart. This is remotely triggerable by an unauthenticated client with a single query against any supergraph that merges an object from two subgraphs, which is the ordinary @shareable or entity case, so it is a denial of service rather than a theoretical hardening issue.

{
  shared {
    fieldA
    constructor: fieldB {
      __proto__: child {
        call: value
      }
    }
  }
}

🎯 Affected products1

  • npm/@graphql-tools/utils:<= 12.0.0

🔗 References (6)