๐Ÿ” CVE Alert

CVE-2026-104852

UNKNOWN 0.0

GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 12.0.1, the GraphQL Tools utils package's mergeDeep function follows inherited properties while recursively merging source objects and does not exclude __proto__, constructor, or prototype keys. An unauthenticated GraphQL client can alias fields to those names so responses from two subgraphs collide during ordinary supergraph result merging, causing mergeDeep to traverse Object and Function prototypes and overwrite Function.prototype.call with a subgraph-supplied value. This breaks subsequent requests in the process until restart. This issue is fixed in version 12.0.1.

CWE CWE-1321
Vendor ardatan
Product graphql-tools
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for ardatan graphql-tools

Be the first to know when new unknown vulnerabilities affecting ardatan graphql-tools are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ardatan / graphql-tools
< 12.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ardatan/graphql-tools/security/advisories/GHSA-7mx3-vvmw-hjmv github.com: https://github.com/ardatan/graphql-tools/pull/8423 github.com: https://github.com/graphql-hive/gateway/pull/2600 github.com: https://github.com/ardatan/graphql-tools/commit/0b9529f1988fd36186a7c106a6efe0356f1b7f2e github.com: https://github.com/ardatan/graphql-tools/releases/tag/@graphql-tools/[email protected]