webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, before query validation and complexity controls run. The resulting SIGSEGV can terminate PHP-FPM workers or long-running Swoole, RoadRunner, ReactPHP, or CLI processes and cannot be caught by application-level exception handling. This issue is fixed in version 15.32.3.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webonyx
Webonyx graphql-php |
|
| Vendors & Products |
Webonyx
Webonyx graphql-php |
Thu, 08 Oct 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, before query validation and complexity controls run. The resulting SIGSEGV can terminate PHP-FPM workers or long-running Swoole, RoadRunner, ReactPHP, or CLI processes and cannot be caught by application-level exception handling. This issue is fixed in version 15.32.3. | |
| Title | webonyx graphql-php: Unbounded recursion in parser causes stack overflow on crafted nested input | |
| Weaknesses | CWE-674 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T18:39:56.356Z
Reserved: 2026-10-07T21:07:54.987Z
Link: CVE-2026-107376
No data.
Status : Awaiting Analysis
Published: 2026-10-08T18:17:22.373
Modified: 2026-10-08T21:34:48.800
Link: CVE-2026-107376
No data.
OpenCVE Enrichment
Updated: 2026-10-08T20:15:06Z
Weaknesses