ID:11869 - Exploit for Allocation of Resources Without Limits or Throttling in GraphQL Java - CVE-2024-40094
Published: August 22, 2025
GraphQL Java
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to GraphQL Java (aka graphql-java) does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.