Vulnerability record · CVE-2026-47707 · published 4 June 2026
CVE-2026-47707: Strawberry graphql uncontrolled resource consumption vulnerability
Strawberry · Strawberry Graphql
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not consider how many times a fragments internal aliases are expanded during execution. this allows an attacker to bypass alias limits and force the server to resolve and render a significantly higher number of aliases than allowed, potentially leading to a dos via resource exhaustion. Version 0.315.7 contains a fix for the issue.
Description
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not consider how many times a fragments internal aliases are expanded during execution. this allows an attacker to bypass alias limits and force the server to resolve and render a significantly higher number of aliases than allowed, potentially leading to a dos via resource exhaustion. Version 0.315.7 contains a fix for the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/strawberry-graphql/strawberry/releases/tag/0.315.7 | ProductRelease Notes |
| https://github.com/strawberry-graphql/strawberry/security/advisories/GHSA-fr49-mhgj-crfc | ExploitVendor Advisory |
| https://github.com/strawberry-graphql/strawberry/security/advisories/GHSA-fr49-mhgj-crfc | ExploitVendor Advisory |
Track CVE-2026-47707 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-47707), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.