CVE-2026-107376
Received Received - Intake

Stack Overflow in GraphQL PHP Parser

Vulnerability report for CVE-2026-107376, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, before query validation and complexity controls run. The resulting SIGSEGV can terminate PHP-FPM workers or long-running Swoole, RoadRunner, ReactPHP, or CLI processes and cannot be caught by application-level exception handling. This issue is fixed in version 15.32.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
webonyx graphql-php < 15.32.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects webonyx graphql-php, a PHP implementation of GraphQL. It allows a remote attacker to submit deeply nested GraphQL queries or types that cause a stack overflow in the PHP process. This happens because the parser does not limit recursion depth during parsing of selection sets, values, or types. The result is a crash (SIGSEGV) that can terminate PHP-FPM workers or long-running PHP processes.

Detection Guidance

Detecting this vulnerability requires checking the version of webonyx graphql-php in use. Run 'composer show webonyx/graphql-php' or check your composer.lock file for the installed version. If the version is below 15.32.3, the system is vulnerable.

Impact Analysis

If you use a vulnerable version of webonyx graphql-php, an attacker could send a specially crafted GraphQL query to crash your PHP server or application. This could lead to downtime, service disruption, or denial of service for your users. Long-running processes like PHP-FPM, Swoole, or ReactPHP are particularly vulnerable.

Mitigation Strategies

Immediately update webonyx graphql-php to version 15.32.3 or later using 'composer update webonyx/graphql-php'. If updating is not possible, consider disabling GraphQL endpoints or implementing network-level restrictions to limit query depth.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107376. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart