CVE-2026-104852
Received Received - Intake

Prototype Pollution in GraphQL Tools MergeDeep Function

Vulnerability report for CVE-2026-104852, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 12.0.1, the GraphQL Tools utils package's mergeDeep function follows inherited properties while recursively merging source objects and does not exclude __proto__, constructor, or prototype keys. An unauthenticated GraphQL client can alias fields to those names so responses from two subgraphs collide during ordinary supergraph result merging, causing mergeDeep to traverse Object and Function prototypes and overwrite Function.prototype.call with a subgraph-supplied value. This breaks subsequent requests in the process until restart. This issue is fixed in version 12.0.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ardatan graphql-tools < 12.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects GraphQL Tools versions before 12.0.1. The mergeDeep function follows inherited properties while merging objects and does not exclude special keys like __proto__, constructor, or prototype. An attacker can exploit this by aliasing fields to those names, causing prototype pollution during supergraph result merging. This overwrites Function.prototype.call with malicious code, breaking subsequent requests until the process restarts.

Detection Guidance

To detect this vulnerability, check if your GraphQL Tools version is below 12.0.1. Use commands like 'npm list @graphql-tools/utils' or 'yarn list @graphql-tools/utils' to verify the installed version. If the version is outdated, update it immediately to 12.0.1 or later.

Impact Analysis

If you use GraphQL Tools versions before 12.0.1, an unauthenticated attacker could disrupt your GraphQL service by causing prototype pollution. This leads to crashes or unexpected behavior in your application until restarted, potentially causing downtime or data corruption.

Compliance Impact

This vulnerability could impact compliance by causing service disruptions or data corruption, which may violate availability requirements in GDPR or HIPAA. Downtime or data loss could lead to non-compliance with these regulations.

Mitigation Strategies

Upgrade GraphQL Tools to version 12.0.1 or later to address the vulnerability in the mergeDeep function.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104852. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart