Summary
CVE-2026-104852 is a prototype pollution vulnerability (CWE-1321) in the mergeDeep utility function shipped in @graphql-tools/utils, part of the widely used GraphQL Tools (ardatan/graphql-tools) library. An unauthenticated remote attacker can craft a GraphQL query that causes mergeDeep to merge attacker-controlled keys such as __proto__, constructor, or prototype into Object.prototype/Function.prototype, corrupting shared JavaScript runtime state. The issue carries a CVSS v4.0 base score of 8.2 (High) and results in a denial-of-service condition affecting the whole process, not just the originating request.
Technical details
- Root cause:
mergeDeeprecursively merged source object keys into a target object without filtering dangerous keys (__proto__,constructor,prototype) and used theinoperator (which traverses the prototype chain) rather thanhasOwnPropertyto decide whether a key already existed on the target. - Trigger conditions: In a federated/stitched GraphQL setup (supergraph), a client can alias response fields to names like
__proto__so that results returned from two different subgraphs collide during ordinary result merging. This causes the polluted key to be written onto a shared object prototype (e.g.,Function.prototype.call). - Attack vector: Network-based, no authentication, and no special user interaction required (CVSS v4.0 vector:
AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N). The attack requires some attacker-controlled conditions (AT:P) — i.e., a gateway that merges/stitches results from multiple subgraphs using the vulnerable merge logic. - Impact: Once a core prototype method (such as
Function.prototype.call) is overwritten, subsequent, unrelated requests handled by the same Node.js process can fail or behave unpredictably until the process is restarted — resulting in a process-wide availability (denial-of-service) impact. The advisory records no confidentiality or integrity impact.
Affected software
@graphql-tools/utilsversions up to and including 12.0.0- Any
ardatan/graphql-toolspackages and downstream consumers (e.g., GraphQL gateway/stitching tools) that depend on the vulnerablemergeDeepimplementation in@graphql-tools/utilsprior to the fix - Fixed in
@graphql-tools/utils12.0.1 and later (with additional hardening released in subsequent 12.0.x versions)
Severity
- CVSS v4.0 Base Score: 8.2 (High)
- Vector:
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N - CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)
Mitigation and recommended actions
- Immediate: Upgrade
@graphql-tools/utils(and any dependent graphql-tools packages) to version 12.0.1 or later. The fix skips source keys named__proto__,constructor, orprototypeat every recursion level inmergeDeep, and replaces theinoperator check withhasOwnPropertyso inherited properties can no longer be used as merge targets. Note that follow-up hardening releases (12.0.2 and 12.0.3) further closed related gaps in incremental-result path merging — upgrading to the latest 12.0.x release is recommended rather than stopping at 12.0.1. - If immediate patching is not possible:
- Restrict or disable field aliasing to reserved prototype-related names (
__proto__,constructor,prototype) at the gateway/proxy layer if such filtering capability exists. - Monitor and alert on unexpected process restarts or request failures in GraphQL gateway/stitching services, which may indicate active exploitation.
- Limit exposure of federated/stitched GraphQL endpoints that merge results from multiple subgraphs to trusted networks where feasible, as the vulnerability specifically affects result-merging logic used in supergraph configurations.
- Restrict or disable field aliasing to reserved prototype-related names (

