ID:11869 - Exploit for Allocation of Resources Without Limits or Throttling in GraphQL Java - CVE-2024-40094

 
Main Vulnerability Database Exploits ID:11869 - Exploit for Allocation of Resources Without Limits or Throttling in GraphQL Java - CVE-2024-40094

ID:11869 - Exploit for Allocation of Resources Without Limits or Throttling in GraphQL Java - CVE-2024-40094

Published: August 22, 2025


Vulnerability identifier: #VU98137
Vulnerability risk: Medium
CVE-ID: CVE-2024-40094
CWE-ID: CWE-770
Exploitation vector: Remote access
Vulnerable software:
GraphQL Java

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to GraphQL Java (aka graphql-java) does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Remediation

Install updates from vendor's website.